Study. uk . com
  1. Home
  2. All questions
  3. Question 797

CISM study material · question 797 of 1000

How does NIST define a vulnerability disclosure?

  1. When an assessor records a weakness in the assessment report that was written for that one particular system
  2. An outside party telling the organisation it suspects a flaw in one of the organisation's systems
  3. When a vendor announces a flaw that has been found in one of its own currently supported software product lines in use today
  4. When the organisation publishes the details of a flaw that it has itself already identified and then repaired
Show the answer

Answer: B. An outside party telling the organisation it suspects a flaw in one of the organisation's systems

SP 800-61r3 uses the term for a report arriving from outside about a suspected weakness in a system the organisation runs.

Source: NIST SP 800-61 Rev. 3 (NIST) — Table 2 ID.RA-08.N1

Challenge yourself on this topic → Study as cards