CGRC · Question #266
Which of the three-tiered approaches to risk management address risk at the IS security control level & their allocation? Response:
The correct answer is A. Information Systems. The "Information Systems" tier in a three-tiered risk management approach specifically addresses risk at the individual information system security control level, focusing on the implementation and allocation of controls. This tier is concerned with the operational…
Question
Which of the three-tiered approaches to risk management address risk at the IS security control level & their allocation? Response:
Options
- AInformation Systems
- BManagement Systems
- CSecurity System
- DFederal Systems
How the community answered
(70 responses)- A87% (61)
- B7% (5)
- C1% (1)
- D4% (3)
Why each option
The "Information Systems" tier in a three-tiered risk management approach specifically addresses risk at the individual information system security control level, focusing on the implementation and allocation of controls. This tier is concerned with the operational effectiveness of security measures directly impacting the system.
In the three-tiered risk management approach defined by frameworks like NIST, the "Information Systems" tier (Tier 3) focuses on managing risk at the individual system level, including the selection, implementation, assessment, and continuous monitoring of security controls and their allocation within specific information systems.
"Management Systems" is not one of the standard three tiers; the tiers are typically Organization-wide (Tier 1), Mission/Business Process (Tier 2), and Information Systems (Tier 3).
"Security System" is a generic term and not one of the defined tiers in the context of a three-tiered risk management approach.
"Federal Systems" describes a category of systems but is not a tier in the standard risk management framework.
Concept tested: Three-tiered risk management approach - Information Systems tier
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.