Study. uk . com
  1. Home
  2. All questions
  3. Question 122

CISSP study material · question 122 of 500

A governance review finds a documented risk tolerance but no statement of risk appetite. What does CSF 2.0 expect under its Risk Management Strategy category?

  1. Both risk appetite and risk tolerance statements, established, communicated and maintained.
  2. A risk tolerance statement only, since appetite is an enterprise finance concept.
  3. Neither, provided the organisation records its residual risk.
  4. A risk appetite statement only, with tolerance derived per system.
Show the answer

Answer: A. Both risk appetite and risk tolerance statements, established, communicated and maintained.

CSF 2.0 asks that risk appetite and risk tolerance statements both be established, communicated and maintained under the Risk Management Strategy category.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.RM-02

Challenge yourself on this topic → Study as cards