(ISC)2
CERTIFIED-IN-CYBERSECURITY · Question #598
What is the purpose of a risk assessment in information security?
The correct answer is A. To establish a risk acceptance threshold. To establish a risk acceptance threshold. A risk assessment is conducted to identify and evaluate potential risks, determine their potential impact, and establish a risk acceptance threshold to guide decision-making in managing those risks.
Security Principles
Question
What is the purpose of a risk assessment in information security?
Options
- ATo establish a risk acceptance threshold
- BTo ensure compliance with regulations
- CTo identify vulnerabilities in systems
- DTo eliminate all risks
How the community answered
(21 responses)- A90% (19)
- B5% (1)
- D5% (1)
Explanation
To establish a risk acceptance threshold. A risk assessment is conducted to identify and evaluate potential risks, determine their potential impact, and establish a risk acceptance threshold to guide decision-making in managing those risks.
Topics
#Risk Assessment#Risk Management#Information Security#Risk Acceptance
Community Discussion
No community discussion yet for this question.