Study. uk . com
  1. Home
  2. All questions
  3. Question 575

CompTIA Security+ study material · question 575 of 611

A risk assessment is commissioned to inform a decision about a single application's deployment. At which tier should it be run?

  1. The information system tier
  2. The mission or business process tier
  3. The organisation tier
  4. The control assessment tier
Show the answer

Answer: A. The information system tier

The tier is chosen by whose decision the results are meant to inform, and this decision belongs to one system.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 § 2.2 Risk Management Hierarchy

Challenge yourself on this topic → Study as cards