- Home
- All questions
- Question 86
CISSP study material · question 86 of 500
A programme manager asks which risk activities their system team owns, given that the enterprise architecture and the risk tolerance are set elsewhere. Which set of activities belongs at Tier 3?
Show the answer
Answer: D. Categorising the system, allocating controls to it, and running selection through to ongoing monitoring.
Tier 3 covers categorisation, control allocation and the life cycle from selection to monitoring. Architecture and process prioritisation are Tier 2; investment strategy is Tier 1.
Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.2 Multitiered Risk Management