- Home
- All questions
- Question 188
CISM study material · question 188 of 1000
The same technical vulnerability is rated critical on one system and low on another. Why is this consistent with SP 800-30?
Show the answer
Answer: C. Severity reflects the harm that would follow from exploitation, which makes it context-dependent
SP 800-30 grades severity by how badly exploitation would hurt, which is a judgement about how urgent mitigation is here. The same flaw therefore rates differently on differently placed systems.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities