CGRC · Question #298
Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat. Response:
The correct answer is A. Threat Assessment. This definition precisely describes a threat assessment, which involves systematically evaluating potential threats, their likelihood, and their potential impact on an information system or enterprise.
Question
Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat. Response:
Options
- AThreat Assessment
- BThreat Event
- CThreat Source
- DThreat Scenario
How the community answered
(58 responses)- A91% (53)
- B5% (3)
- C2% (1)
- D2% (1)
Why each option
This definition precisely describes a threat assessment, which involves systematically evaluating potential threats, their likelihood, and their potential impact on an information system or enterprise.
A threat assessment is a systematic process of identifying and evaluating potential threats, their characteristics, capabilities, and the likelihood they will materialize, to an organization's information systems or assets. Its purpose is to understand the nature of these threats, including their origins and potential impact, enabling informed risk management decisions.
A threat event is an occurrence or incident that results from a threat being actualized, not the process of evaluating threats.
A threat source is the origin or actor responsible for a potential threat, such as a hacker group or a natural disaster, not the assessment process itself.
A threat scenario is a hypothetical situation describing how a specific threat might exploit a vulnerability, used for planning or testing, not the formal evaluation process.
Concept tested: Risk management - threat assessment
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.