From the course: ISACA Certified Information Security Manager (CISM) Cert Prep
Unlock this course with a free trial
Join today to access over 26,100 courses taught by industry experts.
NIST 800-30
From the course: ISACA Certified Information Security Manager (CISM) Cert Prep
NIST 800-30
- [Presenter] After looking at NIST 800-39, we saw that the context was to start with framing the risk. Then we assess the risk, we respond to the risk, and then we monitor. Well, NIST 800-30 specifically focuses on conducting the risk assessment itself. So focusing on assessing the risk, okay? Now, like we said, when we talk about risk assessment, we have to consider that risk assessment ultimately is going to lead us to the point where we can make a good decision on how to mitigate the risk. And so, we also have to keep in mind that risks are only risk as they're risks to the organization. And by that, I mean, we don't focus on IT risks for the sake of focusing on IT risks. We focus on IT risks because they're business risks. So, once again, on this exam and in life, we think about IT as the means to an end. The end is the successful operation of the organization, right? So we focus on risks as they impact the mission, the vision, the strategy of the organization. What we're looking…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
Risk definitions21m 39s
-
(Locked)
Bias5m 31s
-
(Locked)
Developing a risk management program6m 3s
-
(Locked)
NIST 800-397m 12s
-
(Locked)
NIST 800-306m 12s
-
(Locked)
Risk management lifecycle2m 4s
-
(Locked)
Risk assessment and analysis10m 50s
-
(Locked)
NIST SP 800-37 Rev. 1 and SDLC8m 5s
-
(Locked)
Risk response6m 10s
-
(Locked)
Risk action plan7m 5s
-
Risk acceptance9m 12s
-
(Locked)
Risk mitigation4m 29s
-
(Locked)
Risk avoidance, sharing, and transfer9m 37s
-
(Locked)
Risk scenarios7m 39s
-
(Locked)
Risk register6m 15s
-
(Locked)
Cost-benefit analysis and ROI12m 15s
-
(Locked)
Risk monitoring and communications16m 7s
-
(Locked)
Risk governance and management4m 48s
-
(Locked)
Risk review5m 36s
-
-
-
-