Study. uk . com
  1. Home
  2. All questions
  3. Question 196

CISM study material · question 196 of 1000

An analyst proposes mapping every threat to every vulnerability one-to-one across the estate. What does SP 800-30 warn about this approach?

  1. It is required before threat scenarios may be constructed
  2. It scales badly and drives the level of detail rather than letting the organisation use threat information effectively
  3. It understates likelihood by ignoring predisposing conditions, which are what decide whether a given threat-vulnerability pairing could occur
  4. It is the only defensible method at the system level
Show the answer

Answer: B. It scales badly and drives the level of detail rather than letting the organisation use threat information effectively

SP 800-30 warns threat-vulnerability pairing may be undesirable at the business function level and problematic even at system level given the number of threats and vulnerabilities, and that threat scenarios help overcome its limitations.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Likelihood

Challenge yourself on this topic → Study as cards