Study. uk . com
  1. Home
  2. All questions
  3. Question 96

CISSP study material · question 96 of 500

Two teams assess the same platform. One begins by cataloguing adversaries and their methods; the other begins by listing the data the platform holds and what its loss would cost. In SP 800-30 terms, what differs between them?

  1. Their assessment approach: one is quantitative, the other qualitative.
  2. Their analysis approach: one is threat-oriented, the other asset and impact oriented.
  3. Their risk model: one includes predisposing conditions and the other does not.
  4. Their tier: one is assessing at Tier 2 and the other at Tier 3.
Show the answer

Answer: B. Their analysis approach: one is threat-oriented, the other asset and impact oriented.

The analysis approach decides which end of the problem the assessment starts from - threats, assets and impacts, or vulnerabilities. Assessment approach governs the values used, not the starting point.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3 Risk Assessment

Challenge yourself on this topic → Study as cards