- Home
- All questions
- Question 197
CISM study material · question 197 of 1000
Which four consequences does SP 800-30 use to define the level of impact from a threat event?
Show the answer
Answer: A. Unauthorised disclosure, unauthorised modification, destruction, and loss of availability
SP 800-30 defines the level of impact as the magnitude of harm expected from unauthorised disclosure of information, unauthorised modification, unauthorised destruction, or loss of information or system availability.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Impact