nerdexam
(ISC)2

CAP · Question #218

Which of the following NIST documents defines impact?

The correct answer is D. NIST SP 800-30. As with the previous question, NIST SP 800-30 ('Guide for Conducting Risk Assessments') is the document that defines 'impact' in the context of risk management. NIST SP 800-26 is the Security Self-Assessment Guide for IT Systems, NIST SP 800-53A guides the assessment of…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following NIST documents defines impact?

Options

  • ANIST SP 800-26
  • BNIST SP 800-53A
  • CNIST SP 800-53
  • DNIST SP 800-30

How the community answered

(35 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    91% (32)

Explanation

As with the previous question, NIST SP 800-30 ('Guide for Conducting Risk Assessments') is the document that defines 'impact' in the context of risk management. NIST SP 800-26 is the Security Self-Assessment Guide for IT Systems, NIST SP 800-53A guides the assessment of security controls, and NIST SP 800-53 is the security and privacy controls catalog. None of these focus on defining 'impact' the way SP 800-30 does.

Topics

#NIST SP 800-30#Risk Assessment#Impact Definition#NIST Documents

Community Discussion

No community discussion yet for this question.

Full CAP Practice