nerdexam
(ISC)2

CGRC · Question #518

Which NIST SP is a Guide for Conducting. Response:

The correct answer is A. NIST SP 800-30. NIST Special Publication 800-30 provides guidelines for conducting risk assessments for federal information systems and organizations.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which NIST SP is a Guide for Conducting. Response:

Options

  • ANIST SP 800-30
  • BNIST SP 800-37
  • CNIST SP 800-50
  • DNIST SP 800-58

How the community answered

(39 responses)
  • A
    87% (34)
  • B
    3% (1)
  • C
    3% (1)
  • D
    8% (3)

Why each option

NIST Special Publication 800-30 provides guidelines for conducting risk assessments for federal information systems and organizations.

ANIST SP 800-30Correct

NIST Special Publication 800-30, 'Guide for Conducting Risk Assessments,' specifically details a structured approach for identifying, analyzing, and evaluating risks to organizational operations, assets, individuals, other organizations, and the Nation arising from the operation and use of information systems. This publication serves as a foundational guide for performing risk assessments within the broader Risk Management Framework.

BNIST SP 800-37

NIST SP 800-37 is 'Guide for Applying the Risk Management Framework to Federal Information Systems and Organizations,' which outlines the overall RMF process, not specifically risk assessments as its primary title.

CNIST SP 800-50

NIST SP 800-50 is 'Building an Information Technology Security Awareness and Training Program,' which focuses on training programs.

DNIST SP 800-58

NIST SP 800-58 is 'Security Considerations for Voice Over IP Systems,' which focuses on a specific technology's security.

Concept tested: NIST Special Publications - Risk Assessment

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#NIST SP 800-30#Risk Assessment#NIST Publications

Community Discussion

No community discussion yet for this question.

Full CGRC Practice