What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
Steps in Risk Management According to NIST SP 800-30:
Step 1: Prepare for the risk management process.
Step 2: Perform a risk assessment to identify, evaluate, and prioritize risks.
Why Risk Assessment is the Second Step:
It provides a foundational understanding of the risks an organization faces, which informs subsequent steps like mitigation and monitoring.
Why Other Options Are Incorrect:
A. Determine appetite: Part of preparing, not the second step.
B. Evaluate avoidance criteria: Comes after assessing risks.
D. Mitigate risk: Happens after risks are assessed and prioritized.
References:
NIST SP 800-30 provides detailed guidance on performing risk assessments as an integral step in the risk management methodology.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit