Study. uk . com
  1. Home
  2. All questions
  3. Question 295

CISM study material · question 295 of 1000

A stakeholder submits the risk 'I'm concerned about a denial-of-service attack'. Why does IR 8286 say this cannot be analysed as written?

  1. It is expressed outside its context, without the conditions, resources affected or anticipated result
  2. It names a threat rather than a vulnerability, and the register records vulnerabilities as the thing to be treated
  3. It has not been assigned a risk owner, and no entry can be analysed until someone is accountable for taking it forward
  4. It has no numeric likelihood attached
Show the answer

Answer: A. It is expressed outside its context, without the conditions, resources affected or anticipated result

IR 8286 criticises risks expressed outside their context — worrying about floods, or about a denial-of-service attack — stating such examples cannot be analysed or considered without knowing the full picture.

Source: NIST IR 8286 (NIST) — Sec. 3.2.4 Evaluation of Potential Consequences

Challenge yourself on this topic → Study as cards