nerdexam
(ISC)2

CGRC · Question #449

What is the potential impact if the loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational…

The correct answer is D. High. According to federal information system security categorization, a "High" potential impact is assigned when the loss of confidentiality, integrity, or availability would result in severe or catastrophic adverse effects.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What is the potential impact if the loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, individuals, other organizations, or the national security interests of the United States? Response:

Options

  • ALow
  • BModerate
  • CSevere
  • DHigh

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    5% (1)
  • D
    86% (19)

Why each option

According to federal information system security categorization, a "High" potential impact is assigned when the loss of confidentiality, integrity, or availability would result in severe or catastrophic adverse effects.

ALow

A "Low" impact level is associated with a limited adverse effect, not severe or catastrophic.

BModerate

A "Moderate" impact level is associated with a serious adverse effect, but not severe or catastrophic as described in the question.

CSevere

"Severe" is a descriptor used within the definition of "High" impact but is not an impact level itself in the standard FIPS 199 categorization.

DHighCorrect

According to federal information system security categorization guidelines, such as FIPS 199 and NIST SP 800-60, a "High" impact level is assigned when the loss of confidentiality, integrity, or availability is expected to have a severe or catastrophic adverse effect on organizational operations, assets, individuals, other organizations, or national security. This level signifies the most critical potential damage.

Concept tested: FIPS 199 security impact levels

Source: https://nvlpubs.nist.gov/nistpubs/fips/NIST.FIPS.199.pdf

Topics

#Impact Assessment#Risk Management#CIA Triad#Impact Classification

Community Discussion

No community discussion yet for this question.

Full CGRC Practice