Study. uk . com
  1. Home
  2. All questions
  3. Question 130

CISM study material · question 130 of 1000

Personal data exposed by the human resources function damages the whole organisation's reputation, while also making it easier for an attacker to defeat authentication on many systems. Which point does SP 800-39 illustrate with such an example?

  1. Impacts should always be assessed at the system level first, and rolled upward only once the technical loss is known
  2. Reputational impact cannot be assessed alongside technical impact, because the two are measured on scales that do not combine
  3. A single adverse event produces multiple consequences at different levels and in different time frames
  4. Each consequence belongs to a separate, unrelated risk and should be recorded as its own entry in the risk register
Show the answer

Answer: C. A single adverse event produces multiple consequences at different levels and in different time frames

SP 800-39 uses this case to show one event producing several consequences, of different kinds, at different levels and over different horizons — which is why the organisation settles in advance how each is judged.

Source: NIST SP 800-39 (NIST) — Task 1-1 Consequences and Impact

Challenge yourself on this topic → Study as cards