CGRC · Question #350
An occurrence that actually jeopardizes the CIA of an information system or the information system processes that stores or transmits information or that constitutes a violation or imminent threat…
The correct answer is A. Incident. An incident is an occurrence that actually jeopardizes the confidentiality, integrity, or availability of an information system or its data, or indicates a violation of security policies.
Question
An occurrence that actually jeopardizes the CIA of an information system or the information system processes that stores or transmits information or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. Response:
Options
- AIncident
- BData breach
- CCompromise
- DEvent
How the community answered
(34 responses)- A94% (32)
- B3% (1)
- C3% (1)
Why each option
An incident is an occurrence that actually jeopardizes the confidentiality, integrity, or availability of an information system or its data, or indicates a violation of security policies.
An incident is specifically defined as an adverse event that actually or potentially jeopardizes the confidentiality, integrity, or availability (CIA) of an information system or its data, or constitutes a violation or imminent threat of violation of security policies, directly matching the provided description.
A data breach is a specific type of incident involving the unauthorized exposure or exfiltration of sensitive data, but not all security incidents qualify as data breaches.
A compromise indicates that an information system, data, or application has been exposed to unauthorized disclosure, modification, or destruction, which is often a *result* or *state* caused by an incident, not the incident itself.
An event is any observable occurrence in a system or network; while an incident is a type of event, not all events are security incidents (e.g., routine system log entries are events but not incidents).
Concept tested: Definition of a security incident
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.