Study. uk . com
  1. Home
  2. All questions
  3. Question 346

CISM study material · question 346 of 1000

How does SP 800-30 describe the role of security categorisation within risk assessment?

  1. It is an initial summary of impact in terms of failures to meet confidentiality, integrity and availability, used together with threat and vulnerability information
  2. It sets the organisation's own risk tolerance, fixing the level of exposure that may be accepted before any response becomes mandatory, and binding every one of the tiers
  3. It determines the likelihood of threat events, since the category records how attractive the information is to an adversary and therefore how often it will be targeted directly
  4. It replaces the need for a separate impact analysis, since the category already states the harm that would follow a loss of confidentiality, integrity or availability here
Show the answer

Answer: A. It is an initial summary of impact in terms of failures to meet confidentiality, integrity and availability, used together with threat and vulnerability information

SP 800-30 treats the security category as a first cut at impact, expressed as failure against confidentiality, integrity and availability, to be read together with what is known about threats and weaknesses.

Source: NIST SP 800-30 Rev. 1 (NIST) — Task 1-4 Identify Information Sources

Challenge yourself on this topic → Study as cards