CSSLP · Question #48
The organization level is the Tier 1 and it addresses risks from an organizational perspective. What are the various Tier 1 activities? Each correct answer represents a complete solution. Choose all t
The correct answer is A. The organization plans to use the degree and type of oversight, to ensure that the risk management B. The level of risk tolerance. C. The techniques and methodologies an organization plans to employ, to evaluate information system-related. Tier 1 risk management activities, also known as the organizational level, involve defining the organization's risk tolerance, establishing oversight mechanisms for risk management, and determining the methodologies for evaluating information system-related risks. These activitie
Question
The organization level is the Tier 1 and it addresses risks from an organizational perspective. What are the various Tier 1 activities? Each correct answer represents a complete solution. Choose all that apply.
Options
- AThe organization plans to use the degree and type of oversight, to ensure that the risk management
- BThe level of risk tolerance.
- CThe techniques and methodologies an organization plans to employ, to evaluate information system-related
- DThe RMF primarily operates at Tier 1.
How the community answered
(28 responses)- A93% (26)
- D7% (2)
Why each option
Tier 1 risk management activities, also known as the organizational level, involve defining the organization's risk tolerance, establishing oversight mechanisms for risk management, and determining the methodologies for evaluating information system-related risks. These activities set the strategic foundation for managing risk.
Tier 1 activities include establishing the degree and type of oversight to ensure that risk management processes are effective and aligned with organizational goals. This ensures proper governance over risk.
Determining the organization's level of risk tolerance is a fundamental Tier 1 activity, as it defines the acceptable level of risk that the organization is willing to bear. This guides all subsequent risk decisions.
Identifying the techniques and methodologies for evaluating information system-related risks is a strategic Tier 1 activity, providing the framework for how risks will be assessed across the organization. This ensures consistency and effectiveness in risk evaluation.
The Risk Management Framework (RMF) operates across all three tiers (organizational, mission/business process, and information system), not primarily at Tier 1. It provides a comprehensive, structured approach for managing security and privacy risks.
Concept tested: NIST Risk Management Framework Tier 1 activities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.