PROFESSIONAL CERTIFICATION
(SPIPC) EXAM 100% SOLVED.
What is the purpose of the asset assessment
step of the risk management process? - ANSWER• Identify assets requiring protection
and/or that are important to the organization and to national security
• Identify undesirable events and expected impacts
• Prioritize assets based on consequences of loss
What is the purpose of the threat assessment
step of the risk management process? - ANSWER• Determine threats to identified
assets
• Assess intent and capability of identified threats
• Assess current threat level for the identified assets
What is the purpose of the vulnerability
assessment step of the risk management
process? - ANSWER• Identify existing countermeasures and their level of effectiveness
in reducing vulnerabilities
• Identify potential vulnerabilities related to identified assets and their undesirable events
• Identify current vulnerability level for the identified assets that can be exploited by the
identified threats
What is the primary benefit of conducting the risk management process? - ANSWER•
National-level security policy endorses a holistic risk management approach, allowing
decision makers to effectively allocate resources that provide the necessary security to
assets that match the threat to those assets
What are the primary costs of conducting the risk management process? - ANSWER•
Time and effort necessary to execute the five steps of the risk management process
What are the potential challenges security practitioners may face when enacting the risk
management process? - ANSWER• Availability of information necessary to accurately
determine the likelihood and impact of undesirable events
Where can we get information to evaluate an organization's compliance with security
policies? - ANSWER• Self-inspections
What are the major outcomes of the Planning stage of the PPB&E process? -
ANSWER• Office of the Secretary of Defense •• (OSD) and Joint Staff collaboratively