Nist 800 33
5 community-sourced questions and answers. Free — no login.
Risk Assessment within the Risk Management Process
(i) framing risk (ii) assessing risk (iii) responding to risk (iv) monitoring risk.
Risk management processes
describing the environment in which risk-based decisions are made.
frame
The second component of risk management addresses how organizations (_________) risk within the context of the organizational risk frame.
assess
The third component of risk management addresses how organizations (_______) to risk once that risk is determined based on the results of a risk assessment.
respond
The purpose of the (_________) component is to: (i) determine the ongoing effectiveness of risk responses (consistent with the organizational risk frame); (ii) identify risk-impacting changes to organizational information systems and the environments in which the systems operate; and (iii) verify that planned risk responses are implemented and information security requirements derived from and traceable to organizational missions/business functions, federal legislation, directives, regulations, policies, standards, and guidelines are satisfied.
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials