PT0-001 · Question #196
Which of the following documents BEST describes the manner in which a security assessment will be conducted?
The correct answer is A. BIA. A Business Impact Analysis (BIA) defines the criticality and risk thresholds of assets, which directly determines the scope and manner in which a security assessment is structured and conducted.
Question
Which of the following documents BEST describes the manner in which a security assessment will be conducted?
Options
- ABIA
- BSOW
- CSLA
- DMSA
How the community answered
(37 responses)- A89% (33)
- B5% (2)
- C3% (1)
- D3% (1)
Why each option
A Business Impact Analysis (BIA) defines the criticality and risk thresholds of assets, which directly determines the scope and manner in which a security assessment is structured and conducted.
A BIA identifies which systems and processes are critical to operations, defines acceptable risk levels, and establishes the criteria that shape how a security assessment is structured and performed. It is the foundational document that dictates assessment depth, sequencing, and focus areas based on business impact priorities.
A Statement of Work (SOW) is a contractual document specifying deliverables, timelines, and payment terms for a project engagement but does not define the risk-based methodology or priorities that govern how a security assessment is conducted.
A Service Level Agreement (SLA) defines performance expectations and availability guarantees between a service provider and client and does not describe how security assessments are carried out.
A Master Service Agreement (MSA) establishes overarching legal and commercial terms governing a business relationship and does not prescribe the procedures or priorities for individual security assessments.
Concept tested: Business Impact Analysis scope in security assessments
Source: https://csrc.nist.gov/glossary/term/business_impact_analysis
Topics
Community Discussion
No community discussion yet for this question.