nerdexam
(ISC)2

CGRC · Question #281

What are the three parts of Risk Management? Response:

The correct answer is A. 1 - Risk Assessment Methodology. Risk Management is a systematic process typically composed of risk assessment, risk mitigation, and ongoing monitoring and evaluation.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What are the three parts of Risk Management? Response:

Options

  • A1 - Risk Assessment Methodology
  • B1 - Risk Mitigation
  • C1 - Risk Evaluation and Methodology
  • D1 - Risk Executive and Management

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    3% (1)
  • C
    7% (2)

Why each option

Risk Management is a systematic process typically composed of risk assessment, risk mitigation, and ongoing monitoring and evaluation.

A1 - Risk Assessment MethodologyCorrect

Risk Assessment Methodology describes the approach used to identify, analyze, and evaluate risks, serving as the foundational first step in the overall risk management process.

B1 - Risk Mitigation

Risk Mitigation involves implementing controls to reduce risk and occurs after the assessment phase.

C1 - Risk Evaluation and Methodology

While risk evaluation is part of assessment, 'Risk Evaluation and Methodology' is not a standard standalone core part.

D1 - Risk Executive and Management

Risk Executive and Management describes oversight roles, not a phase of the risk management process itself.

Concept tested: Risk Management process phases

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf

Topics

#Risk Management Process#Risk Assessment#Risk Management Components

Community Discussion

No community discussion yet for this question.

Full CGRC Practice