Study. uk . com
  1. Home
  2. All questions
  3. Question 7

CISSP study material · question 7 of 500

A hospital group is chartering an information security continuous monitoring programme. Analysts propose to alert on every configuration change across the estate. The risk officer wants the programme scoped so its output actually drives decisions. Against what should the programme measure what it observes?

  1. The residual risk recorded at the last authorisation, so the original assessment remains the reference
  2. The published breach statistics for the sector, so alerting tracks what comparable operators experience
  3. The organisation's own risk tolerance, so decision-makers learn when a control has fallen outside it
  4. The vendor's recommended hardening baseline, so every deviation from the shipped configuration is reported
Show the answer

Answer: C. The organisation's own risk tolerance, so decision-makers learn when a control has fallen outside it

Continuous monitoring provides standing assurance that controls remain within the organisation's risk tolerance and surfaces what decision-makers need to react promptly; vendor baselines are inputs, not the yardstick.

Source: NIST SP 800-137 (NIST) — SP 800-137 > Abstract

Challenge yourself on this topic → Study as cards