CAP · Question #218
Which of the following NIST documents defines impact?
The correct answer is D. NIST SP 800-30. As with the previous question, NIST SP 800-30 ('Guide for Conducting Risk Assessments') is the document that defines 'impact' in the context of risk management. NIST SP 800-26 is the Security Self-Assessment Guide for IT Systems, NIST SP 800-53A guides the assessment of…
Question
Which of the following NIST documents defines impact?
Options
- ANIST SP 800-26
- BNIST SP 800-53A
- CNIST SP 800-53
- DNIST SP 800-30
How the community answered
(35 responses)- A3% (1)
- C6% (2)
- D91% (32)
Explanation
As with the previous question, NIST SP 800-30 ('Guide for Conducting Risk Assessments') is the document that defines 'impact' in the context of risk management. NIST SP 800-26 is the Security Self-Assessment Guide for IT Systems, NIST SP 800-53A guides the assessment of security controls, and NIST SP 800-53 is the security and privacy controls catalog. None of these focus on defining 'impact' the way SP 800-30 does.
Topics
Community Discussion
No community discussion yet for this question.