nerdexam
(ISC)2

CGRC · Question #191

The potential impact is moderate if-The loss of confidentiality, integrity, or availability could be expected to have a.......................... Response:

The correct answer is A. serious adverse effect on organizational operations, organizational assets, or individuals.. This question defines the "moderate" impact level for security incidents, specifically when the loss of confidentiality, integrity, or availability results in a serious adverse effect.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The potential impact is moderate if-The loss of confidentiality, integrity, or availability could be expected to have a.......................... Response:

Options

  • Aserious adverse effect on organizational operations, organizational assets, or individuals.
  • Bsevere or catastrophic adverse effect on organizational operations, organizational assets, or
  • Cno adverse effect on organizational operations, organizational assets, or individuals.
  • Dlimited adverse effect on organizational operations, organizational assets, or individuals.

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    7% (2)
  • C
    3% (1)

Why each option

This question defines the "moderate" impact level for security incidents, specifically when the loss of confidentiality, integrity, or availability results in a serious adverse effect.

Aserious adverse effect on organizational operations, organizational assets, or individuals.Correct

According to NIST SP 800-60 Vol. 2 Rev. 1, a "serious adverse effect" on organizational operations, assets, or individuals corresponds to a moderate impact level. This level indicates significant degradation of mission capability, minor damage to organizational assets, minor financial loss, or minor harm to individuals, necessitating specific security controls.

Bsevere or catastrophic adverse effect on organizational operations, organizational assets, or

A "severe or catastrophic adverse effect" typically describes a high impact level.

Cno adverse effect on organizational operations, organizational assets, or individuals.

"No adverse effect" would correspond to a low or negligible impact level.

Dlimited adverse effect on organizational operations, organizational assets, or individuals.

A "limited adverse effect" usually corresponds to a low impact level.

Concept tested: NIST impact level definitions

Source: https://csrc.nist.gov/publications/detail/sp/800-60/vol-2/rev-1/final

Topics

#Risk assessment#Impact levels#Moderate impact#CIA triad

Community Discussion

No community discussion yet for this question.

Full CGRC Practice