Study. uk . com
  1. Home
  2. All questions
  3. Question 148

CISSP study material · question 148 of 500

A team reads SP 800-30 as guidance for assessing individual systems only. What does the publication actually say about where risk assessment applies?

  1. It applies only at Tier 3, the information system level.
  2. It applies at all three tiers of the risk management hierarchy, expanding on SP 800-39.
  3. It applies wherever a system is categorised at high impact.
  4. It applies at Tier 1 only, since assessment informs the risk frame.
Show the answer

Answer: B. It applies at all three tiers of the risk management hierarchy, expanding on SP 800-39.

SP 800-30 expects risk assessment to be conducted at every tier of the risk management hierarchy and expands on the guidance in SP 800-39.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > Abstract

Challenge yourself on this topic → Study as cards