Study. uk . com
  1. Home
  2. All questions
  3. Question 563

CompTIA Security+ study material · question 563 of 611

What does the risk executive function provide that individual system authorisations cannot?

  1. Approval of the security assessment report
  2. Selection of the control baseline
  3. A single view of risk across systems, judged against the whole enterprise's tolerance
  4. Technical assessment of each control
Show the answer

Answer: C. A single view of risk across systems, judged against the whole enterprise's tolerance

One system's accepted risk may be reasonable alone and unacceptable when aggregated across the organisation.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 § 2 Fundamentals

Challenge yourself on this topic → Study as cards