Study. uk . com
  1. Home
  2. All questions
  3. Question 197

CISM study material · question 197 of 1000

Which four consequences does SP 800-30 use to define the level of impact from a threat event?

  1. Unauthorised disclosure, unauthorised modification, destruction, and loss of availability
  2. Financial, operational, reputational and legal harm, measured against the organisation's loss thresholds
  3. Direct, indirect, primary and secondary loss
  4. Confidentiality, integrity, availability and accountability, each rated on the same three-point scale
Show the answer

Answer: A. Unauthorised disclosure, unauthorised modification, destruction, and loss of availability

SP 800-30 defines the level of impact as the magnitude of harm expected from unauthorised disclosure of information, unauthorised modification, unauthorised destruction, or loss of information or system availability.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Impact

Challenge yourself on this topic → Study as cards