nerdexam
(ISC)2

CISSP · Question #1201

Which of the following goals represents a modern shift in risk management according to National Institute of Standards and Technology (NIST)?

The correct answer is A. Focus on operating environments that are changing, evolving, and full of emerging threats. NIST's modern risk management framework emphasizes adapting to dynamic, evolving threat landscapes rather than static security postures. This reflects a shift from traditional, compliance-focused approaches to continuous, adaptive risk management.

Submitted by naveen.iyer· Mar 5, 2026Security and Risk Management

Question

Which of the following goals represents a modern shift in risk management according to National Institute of Standards and Technology (NIST)?

Options

  • AFocus on operating environments that are changing, evolving, and full of emerging threats.
  • BSecure information technology (IT) systems that store, process, or transmit organizational
  • CEnable management to make well-informed risk-based decisions justifying security expenditure.
  • DProvide an improved mission accomplishment approach.

How the community answered

(45 responses)
  • A
    89% (40)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Why each option

NIST's modern risk management framework emphasizes adapting to dynamic, evolving threat landscapes rather than static security postures. This reflects a shift from traditional, compliance-focused approaches to continuous, adaptive risk management.

AFocus on operating environments that are changing, evolving, and full of emerging threats.Correct

NIST's modern risk management philosophy, particularly reflected in frameworks like the NIST Risk Management Framework (RMF) and NIST SP 800-37, acknowledges that operating environments are no longer static - they continuously evolve with new technologies, threat actors, and attack vectors. This shift moves away from point-in-time assessments toward continuous monitoring and adaptive security strategies that respond to emerging threats in real time.

BSecure information technology (IT) systems that store, process, or transmit organizational

Securing IT systems that store, process, or transmit data represents a traditional, system-centric security objective aligned with older frameworks like FISMA's original intent, not the modern adaptive risk management shift NIST advocates.

CEnable management to make well-informed risk-based decisions justifying security expenditure.

Enabling management to make risk-based decisions to justify security expenditure is a longstanding goal of risk management and business case development, not a distinguishing characteristic of NIST's modern shift toward dynamic threat environments.

DProvide an improved mission accomplishment approach.

Providing an improved mission accomplishment approach is a general organizational benefit of risk management broadly, but it does not specifically capture NIST's modern emphasis on adapting to evolving and emerging threat landscapes.

Concept tested: NIST modern adaptive risk management framework evolution

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST risk management#Modern risk management#Evolving threats#Dynamic environments

Community Discussion

No community discussion yet for this question.

Full CISSP Practice