Study. uk . com
  1. Home
  2. All questions
  3. Question 89

CISSP study material · question 89 of 500

A distinctly risk-averse bank is choosing anti-malware protection. Which two behaviours does NIST SP 800-39 associate with a less risk-tolerant organisation? Choose two.

  1. Demanding more evidence that a chosen safeguard is genuinely effective.
  2. Deploying products from different vendors at the client and the server.
  3. Accepting a newer product with no track record to gain a capability sooner.
  4. Narrowing the threat list to only those threats peer organisations have actually suffered.
Show the answer

Answer: A. Demanding more evidence that a chosen safeguard is genuinely effective.
B. Deploying products from different vendors at the client and the server.

Less tolerant organisations want more grounds for confidence and may layer different vendors' products. Untested products and a peer-limited threat list are what more tolerant organisations do.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.3.3 Risk Management Strategy

Challenge yourself on this topic → Study as cards