nerdexam
(ISC)2

CGRC · Question #20

The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect; a serious adverse effect, or a severe or catastrophic adverse effect on organizational…

The correct answer is A. Potential Impact. The statement describes the various degrees of harm or damage that could result from a breach of security objectives, encompassing limited, serious, or severe/catastrophic effects, which aligns with the definition of 'Potential Impact' in risk assessment.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect; a serious adverse effect, or a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. Response:

Options

  • APotential Impact
  • BHigh Impact
  • CLow Impact
  • DModerate Impact

How the community answered

(22 responses)
  • A
    91% (20)
  • B
    5% (1)
  • C
    5% (1)

Why each option

The statement describes the various degrees of harm or damage that could result from a breach of security objectives, encompassing limited, serious, or severe/catastrophic effects, which aligns with the definition of 'Potential Impact' in risk assessment.

APotential ImpactCorrect

Potential impact refers to the magnitude of harm that could result from the loss of confidentiality, integrity, or availability of an information system or its data. It encompasses the entire range of possible adverse effects, from limited to severe, on an organization's operations, assets, or individuals.

BHigh Impact

High Impact is a specific level within the potential impact spectrum, indicating a severe or catastrophic adverse effect, not the overarching term for all possible effects.

CLow Impact

Low Impact is a specific level within the potential impact spectrum, indicating a limited adverse effect, not the overarching term for all possible effects.

DModerate Impact

Moderate Impact is a specific level within the potential impact spectrum, indicating a serious adverse effect, not the overarching term for all possible effects.

Concept tested: Information System Impact Levels

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Risk Management#Impact Analysis#Confidentiality, Integrity, Availability#Adverse Effects

Community Discussion

No community discussion yet for this question.

Full CGRC Practice