Study. uk . com
  1. Home
  2. All questions
  3. Question 184

CISM study material · question 184 of 1000

A team restricts its vulnerability register to software defects. Which broader definition does SP 800-30 give?

  1. Any control drawn from the selected baseline that has not yet been implemented on the system, which is carried as a weakness until that implementation closes
  2. Any weakness — in the system, in its security procedures, in internal controls or in how it was built — open to exploitation
  3. Any finding raised by an automated scanner against the running system, since the register exists to track what the tooling has reported
  4. Any condition that increases the likelihood of harm arising, whether or not a threat source would be able to act on it directly at all
Show the answer

Answer: B. Any weakness — in the system, in its security procedures, in internal controls or in how it was built — open to exploitation

SP 800-30 casts the net wider than code: procedural gaps, weak internal controls and implementation flaws all count, provided a threat source could exploit them.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities

Challenge yourself on this topic → Study as cards