Study. uk . com
  1. Home
  2. All questions
  3. Question 123

CISSP study material · question 123 of 500

During a CSF-aligned review, a manager argues that a proposal to move a service to a managed provider is an opportunity, not a risk, and so has no place in the risk discussion. How does CSF 2.0 treat this?

  1. Opportunities belong to enterprise risk management and are out of the framework's scope.
  2. Opportunities are recorded only in the Target Profile, not in risk discussions.
  3. Opportunities are considered only at Tier 4.
  4. Strategic opportunities are positive risk and should be characterised and discussed alongside negative risk.
Show the answer

Answer: D. Strategic opportunities are positive risk and should be characterised and discussed alongside negative risk.

CSF 2.0 asks that strategic opportunities, described as positive risks, be characterised and included in organisational cybersecurity risk discussions.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.RM-07

Challenge yourself on this topic → Study as cards