From the course: ISACA Certified Information Security Manager (CISM) Cert Prep

Unlock this course with a free trial

Join today to access over 26,100 courses taught by industry experts.

NIST 800-30

NIST 800-30

- [Presenter] After looking at NIST 800-39, we saw that the context was to start with framing the risk. Then we assess the risk, we respond to the risk, and then we monitor. Well, NIST 800-30 specifically focuses on conducting the risk assessment itself. So focusing on assessing the risk, okay? Now, like we said, when we talk about risk assessment, we have to consider that risk assessment ultimately is going to lead us to the point where we can make a good decision on how to mitigate the risk. And so, we also have to keep in mind that risks are only risk as they're risks to the organization. And by that, I mean, we don't focus on IT risks for the sake of focusing on IT risks. We focus on IT risks because they're business risks. So, once again, on this exam and in life, we think about IT as the means to an end. The end is the successful operation of the organization, right? So we focus on risks as they impact the mission, the vision, the strategy of the organization. What we're looking…

Contents