Study. uk . com
  1. Home
  2. All questions
  3. Question 128

CISM study material · question 128 of 1000

An assessment scopes vulnerabilities to weaknesses in assets the organisation owns and controls. Which class of vulnerability does SP 800-39 say is being missed?

  1. Vulnerabilities in software still under warranty
  2. Susceptibility to harm from sources outside the organisation's control, such as destruction of infrastructure it does not own
  3. Vulnerabilities that no threat is currently known to exploit, which the assessment excludes because nothing has yet been seen against them
  4. Vulnerabilities already recorded in the corrective action plan, which the assessment excludes because a remediation date has been agreed
Show the answer

Answer: B. Susceptibility to harm from sources outside the organisation's control, such as destruction of infrastructure it does not own

SP 800-39 states vulnerabilities can be associated with an organisation's susceptibility to adverse impacts from external sources, giving the example of physical destruction of non-owned infrastructure such as electric power grids.

Source: NIST SP 800-39 (NIST) — Task 1-1 Vulnerabilities

Challenge yourself on this topic → Study as cards