CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 372


Which of the following goals represents a modern shift in risk management according to National Institute of Standards and Technology (NIST)?

Show Answer
Correct Answer: B

Modern risk management according to the National Institute of Standards and Technology (NIST) reflects a greater focus on operating environments that are changing, evolving, and full of emerging threats. This shift acknowledges the dynamic nature of cybersecurity threats and the necessity for organizations to be adaptive and proactive in their approaches to managing these risks.

Discussion

9 comments
Sign in to comment
LoveguitarOption: C
Sep 13, 2022

C is correct according to NIST SP 800-39

CuteRabbit168Option: B
Oct 3, 2022

Going for B. An update to NIST’s Cybersecurity Framework coming soon: https://www.nextgov.com/cybersecurity/2021/12/nist-outlines-request-information-toward-new-cybersecurity-framework/187427/

klarak
May 6, 2024

Great find. This looks right.

JAckThePip
Oct 6, 2022

think as a manager

WiDeBarulhoOption: B
Oct 25, 2022

There is nothing "modern" in option "C" as that has always been the case. Option "B" addresses more modern risk challenges especially with BYOD and the cloud.

SFTrooperOption: B
Nov 17, 2022

Agree with B due to "shift" at NIST . If not for that would select C

jackdryan
May 14, 2023

B is correct

Nickname53796Option: C
Oct 13, 2022

Goals. Not task.

Mann0302Option: B
Nov 16, 2022

Modern shift = emerging threats. Is nothing new about expenditure. Asking for funds especially for security has always been a problem for companies, is nothing new there until they get hit.

xxxBadManxxxOption: B
Sep 5, 2023

A: According to the National Institute of Standards and Technology (NIST) and modern risk management practices, there is a shift towards a greater focus on operating environments that are changing, evolving, and full of emerging threats. This shift recognizes the dynamic and ever-evolving nature of cybersecurity threats and the need for organizations to adapt to these changes continuously. Option A reflects the idea of embracing a proactive and adaptive approach to risk management, which aligns with modern cybersecurity principles. While the other options (B, C, and D) are important aspects of risk management and security practices, they do not specifically represent the modern shift towards addressing evolving threats and operating environments:

YesPleaseOption: B
Dec 23, 2023

Answer B) https://fedscoop.com/nist-health-cyber-guidance-revision-2/#:~:text=Revision%202%20shifts%20focus%20to%20risk%20management%20of%20environmental%20threats