CGRC · Question #714
Managing information security risk from an organization-wide perspective has to do with the following processes except one. Choose the exception. Response:
The correct answer is D. Mitigating risk. Organization-wide risk management includes framing, assessing, and responding to risk, with mitigating risk being a specific strategy within the broader 'responding to risk' process.
Question
Managing information security risk from an organization-wide perspective has to do with the following processes except one. Choose the exception. Response:
Options
- Aresponding to rist
- BFraming risk
- CAssessing risk
- DMitigating risk
How the community answered
(44 responses)- A2% (1)
- B5% (2)
- C2% (1)
- D91% (40)
Why each option
Organization-wide risk management includes framing, assessing, and responding to risk, with mitigating risk being a specific strategy within the broader 'responding to risk' process.
Responding to risk is a core organizational-level process in risk management, encompassing mitigation, transfer, acceptance, and avoidance.
Framing risk is a foundational organizational-level process that establishes the context for risk management.
Assessing risk is a core organizational-level process involving identifying and analyzing risks.
Organizational risk management processes, as defined by frameworks like NIST, include Framing Risk, Assessing Risk, and Responding to Risk. Mitigating risk is one specific strategy or approach within the broader 'responding to risk' process, not a distinct top-level organizational risk management process itself.
Concept tested: Organizational risk management processes
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.