Study. uk . com
  1. Home
  2. All questions
  3. Question 8

CISSP study material · question 8 of 500

A retailer's risk team has finished assessing a new point-of-sale platform, weighing threats, vulnerabilities, cost against benefit, and the risk remaining once controls are applied. The team lead asks the security architect what the assessment report is entitled to conclude.

  1. An authorisation decision for the platform, since the assessment covered the same control set
  2. A prioritised budget allocation for the controls the assessors judged most cost-effective
  3. A binding determination of which risks the business will accept and which it will remediate
  4. The information executives need to choose a course of action, stopping short of the decision itself
Show the answer

Answer: D. The information executives need to choose a course of action, stopping short of the decision itself

Risk assessment informs rather than decides: it weighs threat, vulnerability, cost-benefit and residual risk, then hands executives what they need to choose. Accepting risk is a separate management act.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > Abstract; Keywords; Supersedes

Challenge yourself on this topic → Study as cards