CGRC · Question #120
A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives are considered when determining possible impact to risk?…
The correct answer is D. Integrity, Confidentiality, and Availability. The question asks about the fundamental security objectives considered by a System Owner when assessing potential impact to risk for a new system.
Question
A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives are considered when determining possible impact to risk? Response:
Options
- ALow, Moderate, and High
- BAuthentication, Authorization, and Accountability
- CCommon, Hybrid, and System-Specific
- DIntegrity, Confidentiality, and Availability
How the community answered
(29 responses)- A7% (2)
- C3% (1)
- D90% (26)
Why each option
The question asks about the fundamental security objectives considered by a System Owner when assessing potential impact to risk for a new system.
Low, Moderate, and High are impact levels, not the underlying objectives used to determine that impact.
Authentication, Authorization, and Accountability (AAA) are security services or principles related to access control and user management, not the primary impact objectives for risk.
Common, Hybrid, and System-Specific refer to types of security controls based on their inheritance or scope, not risk impact objectives.
The core objectives considered when determining the impact of a security event on risk are Confidentiality, Integrity, and Availability (CIA). The potential loss or compromise of any of these three properties defines the adverse effect, which then determines the impact level (low, moderate, or high).
Concept tested: CIA triad as core risk impact objectives
Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
Topics
Community Discussion
No community discussion yet for this question.