- Home
- All questions
- Question 81
CISSP study material · question 81 of 500
A new chief information security officer finds the firm assesses risk once a year at audit time and does nothing with the results until the next audit. She wants to describe, in the vocabulary of NIST SP 800-39, what a complete risk management process should look like. Which set of components should she present?
Show the answer
Answer: C. Framing risk, assessing risk, responding to risk and monitoring risk, run continuously.
SP 800-39 defines four continuous components: frame, assess, respond, monitor. The other lists describe control selection, assessment projects or the authorisation cycle, not the risk management process.
Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.1 Components of Risk Management