- Home
- All questions
- Question 346
CISM study material · question 346 of 1000
How does SP 800-30 describe the role of security categorisation within risk assessment?
Show the answer
Answer: A. It is an initial summary of impact in terms of failures to meet confidentiality, integrity and availability, used together with threat and vulnerability information
SP 800-30 treats the security category as a first cut at impact, expressed as failure against confidentiality, integrity and availability, to be read together with what is known about threats and weaknesses.
Source: NIST SP 800-30 Rev. 1 (NIST) — Task 1-4 Identify Information Sources