Study. uk . com
  1. Home
  2. All questions
  3. Question 86

CISSP study material · question 86 of 500

A programme manager asks which risk activities their system team owns, given that the enterprise architecture and the risk tolerance are set elsewhere. Which set of activities belongs at Tier 3?

  1. Prioritising the organisation's mission and business processes against strategic goals.
  2. Establishing the enterprise architecture with security architecture embedded within it.
  3. Setting the investment strategy for information resources across the organisation.
  4. Categorising the system, allocating controls to it, and running selection through to ongoing monitoring.
Show the answer

Answer: D. Categorising the system, allocating controls to it, and running selection through to ongoing monitoring.

Tier 3 covers categorisation, control allocation and the life cycle from selection to monitoring. Architecture and process prioritisation are Tier 2; investment strategy is Tier 1.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.2 Multitiered Risk Management

Challenge yourself on this topic → Study as cards