- Home
- All questions
- Question 179
CISM study material · question 179 of 1000
How does SP 800-30 characterise a threat source?
Show the answer
Answer: A. Either by intent and method aimed at exploiting a vulnerability, or by a situation and method that might exploit one accidentally
SP 800-30 characterises a threat source as the intent and method targeted at exploiting a vulnerability, or a situation and method that may accidentally exploit one, which is what admits non-adversarial sources.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Threats