nerdexam
(ISC)2

CGRC · Question #112

The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assests, or individuals. Thus the potential…

The correct answer is B. Moderate. The question defines a 'serious adverse effect' from the loss of confidentiality, integrity, or availability, and asks for the corresponding impact level.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assests, or individuals. Thus the potential impact is.. Response:

Options

  • ALow
  • BModerate
  • CHigh
  • DSevere

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    85% (29)
  • C
    3% (1)
  • D
    9% (3)

Why each option

The question defines a 'serious adverse effect' from the loss of confidentiality, integrity, or availability, and asks for the corresponding impact level.

ALow

Low impact typically refers to a limited adverse effect on organizational operations, assets, or individuals.

BModerateCorrect

In risk management frameworks like NIST, a 'serious adverse effect' is typically categorized as a moderate impact. This level indicates that the loss of confidentiality, integrity, or availability would result in significant degradation of organizational capabilities or assets.

CHigh

High impact refers to a severe or catastrophic adverse effect, which is more critical than 'serious'.

DSevere

Severe is usually synonymous with or falls under 'High' impact in these frameworks, but 'serious adverse effect' maps specifically to Moderate.

Concept tested: NIST impact levels for security incidents

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Impact levels#Risk assessment#CIA triad#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice