CGRC · Question #509
Which of the three-tiered approaches to risk management address risk at an Enterprise-wide perspective? Response:
The correct answer is A. Organizational. The Organizational tier of the three-tiered risk management approach addresses risk from an enterprise-wide perspective.
Question
Which of the three-tiered approaches to risk management address risk at an Enterprise-wide perspective? Response:
Options
- AOrganizational
- BCategorization
- CAuthorization
- DInitiation
How the community answered
(32 responses)- A91% (29)
- B6% (2)
- D3% (1)
Why each option
The Organizational tier of the three-tiered risk management approach addresses risk from an enterprise-wide perspective.
NIST Special Publication 800-39 outlines a three-tiered risk management approach, with the Organizational tier (Tier 1) focusing on the enterprise-wide view of risk. This tier involves establishing risk management strategy, governance, and overall risk tolerance for the entire organization.
Categorization is a specific process within risk management, used to classify information and systems, not one of the three overarching tiers of the approach.
Authorization is a critical decision point in the Risk Management Framework, signifying acceptance of risk, but it is not one of the three tiers of risk management.
Initiation refers to the beginning of a process or project, not a defined tier within the three-tiered risk management framework.
Concept tested: NIST Three-Tiered Risk Management - Organizational Tier
Source: https://csrc.nist.gov/publications/detail/sp/800-39/final
Topics
Community Discussion
No community discussion yet for this question.