Study. uk . com
  1. Home
  2. All questions
  3. Question 85

CISSP study material · question 85 of 500

A holding company wants to know which risk activities belong at the organisation level rather than being delegated to divisions or system owners. Which activity sits at Tier 1?

  1. Allocating security controls to a particular information system.
  2. Determining the organisation's risk tolerance as part of the risk management strategy.
  3. Deciding what information a business process needs and how sensitive it is.
  4. Assessing whether the controls on a system are implemented correctly.
Show the answer

Answer: B. Determining the organisation's risk tolerance as part of the risk management strategy.

Tier 1 is where framing happens, including governance and the tolerance decision. Allocating and assessing controls is Tier 3 work; deciding what information a process needs is Tier 2.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.3 Tier One - Organization View

Challenge yourself on this topic → Study as cards