nerdexam
(ISC)2

CGRC · Question #580

Which of the following is not a risk factor as stated in NIST SP 800-37? Response:

The correct answer is D. Threat actor. In the context of risk assessment as defined by NIST SP 800-37, key risk factors typically include threat, vulnerability, and the likelihood and impact of a threat exploiting a vulnerability. A 'threat actor' is the source of a threat, not a distinct risk factor itself.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is not a risk factor as stated in NIST SP 800-37? Response:

Options

  • AThreat
  • BLikelihood
  • CVulnerability
  • DThreat actor

How the community answered

(37 responses)
  • B
    3% (1)
  • C
    5% (2)
  • D
    92% (34)

Why each option

In the context of risk assessment as defined by NIST SP 800-37, key risk factors typically include threat, vulnerability, and the likelihood and impact of a threat exploiting a vulnerability. A 'threat actor' is the source of a threat, not a distinct risk factor itself.

AThreat

Threat is a fundamental component of risk, representing any circumstance or event with the potential to cause harm.

BLikelihood

Likelihood is a crucial risk factor, describing the probability that a given threat will exploit a vulnerability.

CVulnerability

Vulnerability is a key risk factor, referring to a weakness that can be exploited by a threat.

DThreat actorCorrect

NIST SP 800-37 defines risk as a function of the likelihood of a threat source exploiting a vulnerability and the resulting impact. The core risk factors are generally understood as threat, vulnerability, and impact, often combined with likelihood. A 'threat actor' is the entity (human or otherwise) that initiates a threat, not a separate primary risk factor.

Concept tested: NIST risk factors definition

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk factors#Risk Management Framework#Threat, Vulnerability, Likelihood

Community Discussion

No community discussion yet for this question.

Full CGRC Practice