nerdexam
(ISC)2

CGRC · Question #683

What publication provides an approach for performing system-level risk assessments? Response:

The correct answer is A. NIST SP 800-30. NIST SP 800-30 provides a guide for conducting risk assessments, specifically detailing an approach for identifying, analyzing, and mitigating risks at the system level.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What publication provides an approach for performing system-level risk assessments? Response:

Options

  • ANIST SP 800-30
  • BNIST SP 800-39
  • CNIST SP 800-60
  • DNIST SP 800-50

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    4% (1)
  • D
    8% (2)

Why each option

NIST SP 800-30 provides a guide for conducting risk assessments, specifically detailing an approach for identifying, analyzing, and mitigating risks at the system level.

ANIST SP 800-30Correct

NIST Special Publication 800-30, 'Guide for Conducting Risk Assessments,' details a nine-step process for performing risk assessments, which includes preparing for the assessment, conducting the assessment, and communicating the results. This publication specifically targets an approach for system-level risk assessments to identify threats and vulnerabilities.

BNIST SP 800-39

NIST SP 800-39, 'Managing Information Security Risk,' provides an organization-wide program for managing information security risk, not specifically the methodology for system-level assessments.

CNIST SP 800-60

NIST SP 800-60, 'Guide for Mapping Types of Information and Information Systems to Security Categories,' provides guidance on categorizing information and information systems, not on risk assessment methodology.

DNIST SP 800-50

NIST SP 800-50, 'Building an Information Technology Security Awareness and Training Program,' focuses on security awareness and training, which is unrelated to performing risk assessments.

Concept tested: NIST SP 800-30 Risk Assessment Methodology

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev1/final

Topics

#NIST Special Publications#Risk Assessment#System-level Risk#Information Security Guidance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice