- Home
- All questions
- Question 184
CISM study material · question 184 of 1000
A team restricts its vulnerability register to software defects. Which broader definition does SP 800-30 give?
Show the answer
Answer: B. Any weakness — in the system, in its security procedures, in internal controls or in how it was built — open to exploitation
SP 800-30 casts the net wider than code: procedural gaps, weak internal controls and implementation flaws all count, provided a threat source could exploit them.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities