- Home
- All questions
- Question 636
CISM study material · question 636 of 1000
On what basis is a system rated low, moderate or high against each security objective?
Show the answer
Answer: A. The expected severity of the adverse effect on organisational operations, assets or individuals
NIST's categorisation rates the potential impact for confidentiality, integrity and availability by whether unauthorised disclosure, modification or loss could be expected to have a limited, serious or severe adverse effect on operations, assets or individuals.
Source: NIST SP 800-100 (NIST) — Table 8-2 FIPS 199 Categorization