nerdexam
(ISC)2

CGRC · Question #423

One of the inputs to the risk determination task is the employment of risk assessments to provide information that may influence the risk analysis and risk determination. What publication provides…

The correct answer is D. NIST SP 800-30. NIST Special Publication 800-30 provides comprehensive guidance on how to conduct risk assessments for federal information systems and organizations. This publication details the risk assessment process, including risk analysis and risk determination.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

One of the inputs to the risk determination task is the employment of risk assessments to provide information that may influence the risk analysis and risk determination. What publication provides guidance on conducting risk assessments? Response:

Options

  • ANIST SP 800-39
  • BNIST SP 800-59
  • CNIST SP 800-37
  • DNIST SP 800-30

How the community answered

(39 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    87% (34)

Why each option

NIST Special Publication 800-30 provides comprehensive guidance on how to conduct risk assessments for federal information systems and organizations. This publication details the risk assessment process, including risk analysis and risk determination.

ANIST SP 800-39

NIST SP 800-39 focuses on managing organizational risk, including enterprise-wide risk management, not specifically on conducting individual system-level risk assessments.

BNIST SP 800-59

NIST SP 800-59 provides guidance on identifying information and information systems as national security systems, which is unrelated to conducting risk assessments.

CNIST SP 800-37

NIST SP 800-37 focuses on the Risk Management Framework (RMF) for federal information systems, which includes risk assessment as one step, but 800-30 provides the detailed guidance on conducting the assessment itself.

DNIST SP 800-30Correct

NIST Special Publication 800-30, titled 'Guide for Conducting Risk Assessments,' is the authoritative document that outlines the methodology and steps for performing risk assessments. It details how to identify threats, vulnerabilities, likelihood, impact, and ultimately determine risk.

Concept tested: NIST Risk Assessment Guidance

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#NIST SP 800-30#Risk Assessment#Risk Management#NIST Publications

Community Discussion

No community discussion yet for this question.

Full CGRC Practice