nerdexam
(ISC)2

CGRC · Question #360

The System Owner (SO) of Colvine Tech is implementing a new system in the organization's Information Technology (IT) environment. What objectives are considered when determining possible impact to ris

The correct answer is A. Integrity, Confidentiality, and Availability (CIA). When a System Owner implements a new system, the primary objectives considered for impact to risk are the fundamental elements of information security.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The System Owner (SO) of Colvine Tech is implementing a new system in the organization's Information Technology (IT) environment. What objectives are considered when determining possible impact to risk? Response:

Options

  • AIntegrity, Confidentiality, and Availability (CIA)
  • BCommon, Hybrid, and System-Specific
  • CAuthentication, Authorization, and Accountability
  • DLow, Moderate, and High

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • C
    3% (1)

Why each option

When a System Owner implements a new system, the primary objectives considered for impact to risk are the fundamental elements of information security.

AIntegrity, Confidentiality, and Availability (CIA)Correct

When determining the possible impact to risk for a new system, the System Owner considers the fundamental objectives of information security: Confidentiality, Integrity, and Availability (CIA). Assessing how a system's failure or compromise affects these three principles-preventing unauthorized disclosure (confidentiality), unauthorized modification (integrity), and ensuring timely access (availability)-helps quantify the potential impact on organizational operations and assets, thereby informing risk decisions.

BCommon, Hybrid, and System-Specific

Common, Hybrid, and System-Specific refer to different categories of security controls, not the objectives considered when assessing risk impact.

CAuthentication, Authorization, and Accountability

Authentication, Authorization, and Accountability are security services or mechanisms that contribute to achieving CIA, but they are not the primary objectives for impact assessment themselves.

DLow, Moderate, and High

Low, Moderate, and High are levels or categories of risk or impact, not the fundamental objectives that are being evaluated for potential impact.

Concept tested: CIA triad in risk assessment

Source: https://csrc.nist.gov/glossary/term/confidentiality_integrity_and_availability

Topics

#CIA Triad#Risk Assessment#Impact Analysis#Information Security Objectives

Community Discussion

No community discussion yet for this question.

Full CGRC Practice