nerdexam
(ISC)2

CGRC · Question #120

A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives are considered when determining possible impact to risk?…

The correct answer is D. Integrity, Confidentiality, and Availability. The question asks about the fundamental security objectives considered by a System Owner when assessing potential impact to risk for a new system.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives are considered when determining possible impact to risk? Response:

Options

  • ALow, Moderate, and High
  • BAuthentication, Authorization, and Accountability
  • CCommon, Hybrid, and System-Specific
  • DIntegrity, Confidentiality, and Availability

How the community answered

(29 responses)
  • A
    7% (2)
  • C
    3% (1)
  • D
    90% (26)

Why each option

The question asks about the fundamental security objectives considered by a System Owner when assessing potential impact to risk for a new system.

ALow, Moderate, and High

Low, Moderate, and High are impact levels, not the underlying objectives used to determine that impact.

BAuthentication, Authorization, and Accountability

Authentication, Authorization, and Accountability (AAA) are security services or principles related to access control and user management, not the primary impact objectives for risk.

CCommon, Hybrid, and System-Specific

Common, Hybrid, and System-Specific refer to types of security controls based on their inheritance or scope, not risk impact objectives.

DIntegrity, Confidentiality, and AvailabilityCorrect

The core objectives considered when determining the impact of a security event on risk are Confidentiality, Integrity, and Availability (CIA). The potential loss or compromise of any of these three properties defines the adverse effect, which then determines the impact level (low, moderate, or high).

Concept tested: CIA triad as core risk impact objectives

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Risk Impact#CIA Triad#Information Security Objectives#System Owner

Community Discussion

No community discussion yet for this question.

Full CGRC Practice