- Home
- All questions
- Question 122
CISSP study material · question 122 of 500
A governance review finds a documented risk tolerance but no statement of risk appetite. What does CSF 2.0 expect under its Risk Management Strategy category?
Show the answer
Answer: A. Both risk appetite and risk tolerance statements, established, communicated and maintained.
CSF 2.0 asks that risk appetite and risk tolerance statements both be established, communicated and maintained under the Risk Management Strategy category.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.RM-02