Study. uk . com
  1. Home
  2. All questions
  3. Question 171

CISM study material · question 171 of 1000

A team debating a risk rating cannot agree because they are weighing threat capability, control maturity and asset value simultaneously. Under SP 800-30, which two factors is risk actually a function of?

  1. Exposure and residual risk
  2. Threat capability and control maturity, combined into a single exposure score held for each asset
  3. The adverse impact if the event occurs, and the likelihood of it occurring
  4. Asset value and vulnerability severity
Show the answer

Answer: C. The adverse impact if the event occurs, and the likelihood of it occurring

SP 800-30 defines risk as a function of the adverse impacts that would arise if a circumstance or event occurs and the likelihood of occurrence. Every other factor feeds one of those two.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3 Key Risk Concepts

Challenge yourself on this topic → Study as cards