nerdexam
(ISC)2

CGRC · Question #266

Which of the three-tiered approaches to risk management address risk at the IS security control level & their allocation? Response:

The correct answer is A. Information Systems. The "Information Systems" tier in a three-tiered risk management approach specifically addresses risk at the individual information system security control level, focusing on the implementation and allocation of controls. This tier is concerned with the operational…

Selection and Approval of Framework, Security, and Privacy Controls

Question

Which of the three-tiered approaches to risk management address risk at the IS security control level & their allocation? Response:

Options

  • AInformation Systems
  • BManagement Systems
  • CSecurity System
  • DFederal Systems

How the community answered

(70 responses)
  • A
    87% (61)
  • B
    7% (5)
  • C
    1% (1)
  • D
    4% (3)

Why each option

The "Information Systems" tier in a three-tiered risk management approach specifically addresses risk at the individual information system security control level, focusing on the implementation and allocation of controls. This tier is concerned with the operational effectiveness of security measures directly impacting the system.

AInformation SystemsCorrect

In the three-tiered risk management approach defined by frameworks like NIST, the "Information Systems" tier (Tier 3) focuses on managing risk at the individual system level, including the selection, implementation, assessment, and continuous monitoring of security controls and their allocation within specific information systems.

BManagement Systems

"Management Systems" is not one of the standard three tiers; the tiers are typically Organization-wide (Tier 1), Mission/Business Process (Tier 2), and Information Systems (Tier 3).

CSecurity System

"Security System" is a generic term and not one of the defined tiers in the context of a three-tiered risk management approach.

DFederal Systems

"Federal Systems" describes a category of systems but is not a tier in the standard risk management framework.

Concept tested: Three-tiered risk management approach - Information Systems tier

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf

Topics

#Three-tiered risk management#NIST RMF tiers#Information System tier#Security control allocation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice