CGRC · Question #403
In which step of the NIST SP 800-30 Risk Assessment process are vulnerabilities paired with threats? Response:
The correct answer is D. Impact Analysis. In the NIST SP 800-30 Risk Assessment process, vulnerabilities are paired with threats during the Impact Analysis step to determine the potential adverse effects resulting from a threat exploiting a vulnerability. This step focuses on understanding the magnitude of harm if a…
Question
In which step of the NIST SP 800-30 Risk Assessment process are vulnerabilities paired with threats? Response:
Options
- ALikelihood Determination
- BVulnerability Identification
- CEvaluation and Assessment
- DImpact Analysis
How the community answered
(33 responses)- B3% (1)
- C3% (1)
- D94% (31)
Why each option
In the NIST SP 800-30 Risk Assessment process, vulnerabilities are paired with threats during the Impact Analysis step to determine the potential adverse effects resulting from a threat exploiting a vulnerability. This step focuses on understanding the magnitude of harm if a threat-vulnerability pair materializes.
Likelihood Determination focuses on the probability that a threat will exploit a vulnerability, not the pairing itself.
Vulnerability Identification is the process of discovering weaknesses, not combining them with threats to determine consequences.
Evaluation and Assessment is a broader term that encompasses the entire risk assessment but is not the specific step where threats and vulnerabilities are initially paired for impact determination.
In the NIST SP 800-30 Risk Assessment process, Impact Analysis involves analyzing the potential adverse effects on organizational operations, assets, or individuals that could result if a threat source exploits a vulnerability. This step implicitly, if not explicitly, involves considering the specific vulnerabilities that threats could leverage to cause impact.
Concept tested: NIST SP 800-30 Impact Analysis
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.