nerdexam
(ISC)2

CSSLP · Question #48

The organization level is the Tier 1 and it addresses risks from an organizational perspective. What are the various Tier 1 activities? Each correct answer represents a complete solution. Choose all t

The correct answer is A. The organization plans to use the degree and type of oversight, to ensure that the risk management B. The level of risk tolerance. C. The techniques and methodologies an organization plans to employ, to evaluate information system-related. Tier 1 risk management activities, also known as the organizational level, involve defining the organization's risk tolerance, establishing oversight mechanisms for risk management, and determining the methodologies for evaluating information system-related risks. These activitie

Secure Software Lifecycle Management

Question

The organization level is the Tier 1 and it addresses risks from an organizational perspective. What are the various Tier 1 activities? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AThe organization plans to use the degree and type of oversight, to ensure that the risk management
  • BThe level of risk tolerance.
  • CThe techniques and methodologies an organization plans to employ, to evaluate information system-related
  • DThe RMF primarily operates at Tier 1.

How the community answered

(28 responses)
  • A
    93% (26)
  • D
    7% (2)

Why each option

Tier 1 risk management activities, also known as the organizational level, involve defining the organization's risk tolerance, establishing oversight mechanisms for risk management, and determining the methodologies for evaluating information system-related risks. These activities set the strategic foundation for managing risk.

AThe organization plans to use the degree and type of oversight, to ensure that the risk managementCorrect

Tier 1 activities include establishing the degree and type of oversight to ensure that risk management processes are effective and aligned with organizational goals. This ensures proper governance over risk.

BThe level of risk tolerance.Correct

Determining the organization's level of risk tolerance is a fundamental Tier 1 activity, as it defines the acceptable level of risk that the organization is willing to bear. This guides all subsequent risk decisions.

CThe techniques and methodologies an organization plans to employ, to evaluate information system-relatedCorrect

Identifying the techniques and methodologies for evaluating information system-related risks is a strategic Tier 1 activity, providing the framework for how risks will be assessed across the organization. This ensures consistency and effectiveness in risk evaluation.

DThe RMF primarily operates at Tier 1.

The Risk Management Framework (RMF) operates across all three tiers (organizational, mission/business process, and information system), not primarily at Tier 1. It provides a comprehensive, structured approach for managing security and privacy risks.

Concept tested: NIST Risk Management Framework Tier 1 activities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf

Topics

#Risk Management#Organizational Risk#Tier 1 Activities#Risk Tolerance

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice