- Home
- All questions
- Question 8
CISSP study material · question 8 of 500
A retailer's risk team has finished assessing a new point-of-sale platform, weighing threats, vulnerabilities, cost against benefit, and the risk remaining once controls are applied. The team lead asks the security architect what the assessment report is entitled to conclude.
Show the answer
Answer: D. The information executives need to choose a course of action, stopping short of the decision itself
Risk assessment informs rather than decides: it weighs threat, vulnerability, cost-benefit and residual risk, then hands executives what they need to choose. Accepting risk is a separate management act.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > Abstract; Keywords; Supersedes