CGRC · Question #20
The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect; a serious adverse effect, or a severe or catastrophic adverse effect on organizational…
The correct answer is A. Potential Impact. The statement describes the various degrees of harm or damage that could result from a breach of security objectives, encompassing limited, serious, or severe/catastrophic effects, which aligns with the definition of 'Potential Impact' in risk assessment.
Question
The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect; a serious adverse effect, or a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. Response:
Options
- APotential Impact
- BHigh Impact
- CLow Impact
- DModerate Impact
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- C5% (1)
Why each option
The statement describes the various degrees of harm or damage that could result from a breach of security objectives, encompassing limited, serious, or severe/catastrophic effects, which aligns with the definition of 'Potential Impact' in risk assessment.
Potential impact refers to the magnitude of harm that could result from the loss of confidentiality, integrity, or availability of an information system or its data. It encompasses the entire range of possible adverse effects, from limited to severe, on an organization's operations, assets, or individuals.
High Impact is a specific level within the potential impact spectrum, indicating a severe or catastrophic adverse effect, not the overarching term for all possible effects.
Low Impact is a specific level within the potential impact spectrum, indicating a limited adverse effect, not the overarching term for all possible effects.
Moderate Impact is a specific level within the potential impact spectrum, indicating a serious adverse effect, not the overarching term for all possible effects.
Concept tested: Information System Impact Levels
Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
Topics
Community Discussion
No community discussion yet for this question.