Study. uk . com
  1. Home
  2. All questions
  3. Question 81

CISSP study material · question 81 of 500

A new chief information security officer finds the firm assesses risk once a year at audit time and does nothing with the results until the next audit. She wants to describe, in the vocabulary of NIST SP 800-39, what a complete risk management process should look like. Which set of components should she present?

  1. Planning the assessment, executing it, reporting the findings and closing the findings.
  2. Categorising the system, selecting controls, authorising it and reauthorising every three years.
  3. Framing risk, assessing risk, responding to risk and monitoring risk, run continuously.
  4. Identifying assets, classifying them, applying controls and auditing the controls annually.
Show the answer

Answer: C. Framing risk, assessing risk, responding to risk and monitoring risk, run continuously.

SP 800-39 defines four continuous components: frame, assess, respond, monitor. The other lists describe control selection, assessment projects or the authorisation cycle, not the risk management process.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.1 Components of Risk Management

Challenge yourself on this topic → Study as cards