medium
Single Answer
0Kimon is developing a continuous security monitoring strategy for his organization. Which one of the following is not normally used when determining assessment and monitoring frequency?
Answer Options
A
Threat intelligence
B
System categorization/impact level
C
Security control operational burden
D
Organizational risk tolerance
Correct Answer: C
Explanation
According to NIST SP 800-137, organizations should use factors such as security control volatility, system categorization/impact levels, security controls providing critical functions, controls with identified weaknesses, organizational risk tolerance, threat information, vulnerability information, risk assessment results, the output of monitoring strategy reviews, and reporting requirements to determine assessment and monitoring frequency. Security control operational burden is not typically used as a factor.