nerdexam
(ISC)2

CGRC · Question #14

Where would you find standard guidance for determining an organization's risk appetite? Response:

The correct answer is A. NIST SP 800-39. NIST SP 800-39 provides comprehensive guidance on managing information security risk across an organization, including the establishment of risk appetite and risk tolerance levels. It outlines a holistic approach to risk management.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Where would you find standard guidance for determining an organization's risk appetite? Response:

Options

  • ANIST SP 800-39
  • BNIST SP 800-50
  • CNIST SP 800-37
  • DNIST SP 800-53

How the community answered

(55 responses)
  • A
    93% (51)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Why each option

NIST SP 800-39 provides comprehensive guidance on managing information security risk across an organization, including the establishment of risk appetite and risk tolerance levels. It outlines a holistic approach to risk management.

ANIST SP 800-39Correct

NIST SP 800-39, 'Managing Information Security Risk: Organization, Mission, and System View,' is the primary NIST special publication that provides a holistic framework for managing information security risk. It offers guidance for defining risk appetite and tolerance at organizational levels.

BNIST SP 800-50

NIST SP 800-50 is 'Building an Information Technology Security Awareness and Training Program,' which focuses on personnel education, not risk appetite determination.

CNIST SP 800-37

NIST SP 800-37, 'Risk Management Framework for Information Systems and Organizations,' describes the RMF process for systems, but SP 800-39 is the overarching guidance for defining an organization's risk appetite.

DNIST SP 800-53

NIST SP 800-53, 'Security and Privacy Controls for Information Systems and Organizations,' lists specific security controls, but does not primarily guide the determination of an organization's overall risk appetite.

Concept tested: NIST Risk Management Publications

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf

Topics

#NIST SP 800-39#Risk Appetite#Risk Management#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice