Study. uk . com
  1. Home
  2. All questions
  3. Question 94

CISSP study material · question 94 of 500

A consultancy is asked to document the risk assessment methodology it will use for a client. Which four elements does NIST SP 800-30 expect that methodology to contain?

  1. A scope statement, a threat catalogue, a control catalogue and a residual risk register.
  2. An assessment process, a risk model, an assessment approach and an analysis approach.
  3. A likelihood scale, an impact scale, a risk matrix and an acceptance threshold.
  4. A charter, a schedule, a staffing plan and a reporting template.
Show the answer

Answer: B. An assessment process, a risk model, an assessment approach and an analysis approach.

SP 800-30 names the process, the risk model, the assessment approach and the analysis approach. The other lists describe project artefacts or one particular scoring scheme.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3 Risk Assessment

Challenge yourself on this topic → Study as cards