nerdexam
(ISC)2

CGRC · Question #509

Which of the three-tiered approaches to risk management address risk at an Enterprise-wide perspective? Response:

The correct answer is A. Organizational. The Organizational tier of the three-tiered risk management approach addresses risk from an enterprise-wide perspective.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the three-tiered approaches to risk management address risk at an Enterprise-wide perspective? Response:

Options

  • AOrganizational
  • BCategorization
  • CAuthorization
  • DInitiation

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    6% (2)
  • D
    3% (1)

Why each option

The Organizational tier of the three-tiered risk management approach addresses risk from an enterprise-wide perspective.

AOrganizationalCorrect

NIST Special Publication 800-39 outlines a three-tiered risk management approach, with the Organizational tier (Tier 1) focusing on the enterprise-wide view of risk. This tier involves establishing risk management strategy, governance, and overall risk tolerance for the entire organization.

BCategorization

Categorization is a specific process within risk management, used to classify information and systems, not one of the three overarching tiers of the approach.

CAuthorization

Authorization is a critical decision point in the Risk Management Framework, signifying acceptance of risk, but it is not one of the three tiers of risk management.

DInitiation

Initiation refers to the beginning of a process or project, not a defined tier within the three-tiered risk management framework.

Concept tested: NIST Three-Tiered Risk Management - Organizational Tier

Source: https://csrc.nist.gov/publications/detail/sp/800-39/final

Topics

#Risk Management Tiers#Enterprise Risk Management#NIST RMF#Organizational Risk

Community Discussion

No community discussion yet for this question.

Full CGRC Practice