CGRC · Question #14
Where would you find standard guidance for determining an organization's risk appetite? Response:
The correct answer is A. NIST SP 800-39. NIST SP 800-39 provides comprehensive guidance on managing information security risk across an organization, including the establishment of risk appetite and risk tolerance levels. It outlines a holistic approach to risk management.
Question
Where would you find standard guidance for determining an organization's risk appetite? Response:
Options
- ANIST SP 800-39
- BNIST SP 800-50
- CNIST SP 800-37
- DNIST SP 800-53
How the community answered
(55 responses)- A93% (51)
- B2% (1)
- C4% (2)
- D2% (1)
Why each option
NIST SP 800-39 provides comprehensive guidance on managing information security risk across an organization, including the establishment of risk appetite and risk tolerance levels. It outlines a holistic approach to risk management.
NIST SP 800-39, 'Managing Information Security Risk: Organization, Mission, and System View,' is the primary NIST special publication that provides a holistic framework for managing information security risk. It offers guidance for defining risk appetite and tolerance at organizational levels.
NIST SP 800-50 is 'Building an Information Technology Security Awareness and Training Program,' which focuses on personnel education, not risk appetite determination.
NIST SP 800-37, 'Risk Management Framework for Information Systems and Organizations,' describes the RMF process for systems, but SP 800-39 is the overarching guidance for defining an organization's risk appetite.
NIST SP 800-53, 'Security and Privacy Controls for Information Systems and Organizations,' lists specific security controls, but does not primarily guide the determination of an organization's overall risk appetite.
Concept tested: NIST Risk Management Publications
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.