CGRC · Question #3
The Organization Level (Tier 1) strategy addresses/requires........ Response:
The correct answer is A. *Assessment of Risks. The Organization Level (Tier 1) strategy, in the context of risk management, primarily focuses on establishing the risk management strategy and governance, which includes the assessment of risks across the enterprise.
Question
The Organization Level (Tier 1) strategy addresses/requires........ Response:
Options
- A*Assessment of Risks
- B*Mitigation of Risks
- C*Acceptance of Risk
- D*Evaluation of Risks
How the community answered
(40 responses)- A95% (38)
- B3% (1)
- D3% (1)
Why each option
The Organization Level (Tier 1) strategy, in the context of risk management, primarily focuses on establishing the risk management strategy and governance, which includes the assessment of risks across the enterprise.
At the Organization Level (Tier 1), risk management primarily involves establishing the overall risk management strategy, policies, and an organization-wide assessment of risks to inform strategic decision-making. This tier sets the foundation for how risks are identified and evaluated across the entire enterprise.
Mitigation of risks is typically addressed at the mission/business process (Tier 2) or information system (Tier 3) levels, where specific controls are implemented.
Acceptance of risk is a risk response decision made after risks have been assessed and potential mitigation strategies considered, not the primary activity of Tier 1 strategy.
Evaluation of risks is part of the broader risk assessment process, which occurs at Tier 1, but 'Assessment of Risks' is a more direct and encompassing term for the core activity at this level.
Concept tested: NIST RMF Tier 1 activities - risk assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-39/final
Topics
Community Discussion
No community discussion yet for this question.