CGRC · Question #580
Which of the following is not a risk factor as stated in NIST SP 800-37? Response:
The correct answer is D. Threat actor. In the context of risk assessment as defined by NIST SP 800-37, key risk factors typically include threat, vulnerability, and the likelihood and impact of a threat exploiting a vulnerability. A 'threat actor' is the source of a threat, not a distinct risk factor itself.
Question
Which of the following is not a risk factor as stated in NIST SP 800-37? Response:
Options
- AThreat
- BLikelihood
- CVulnerability
- DThreat actor
How the community answered
(37 responses)- B3% (1)
- C5% (2)
- D92% (34)
Why each option
In the context of risk assessment as defined by NIST SP 800-37, key risk factors typically include threat, vulnerability, and the likelihood and impact of a threat exploiting a vulnerability. A 'threat actor' is the source of a threat, not a distinct risk factor itself.
Threat is a fundamental component of risk, representing any circumstance or event with the potential to cause harm.
Likelihood is a crucial risk factor, describing the probability that a given threat will exploit a vulnerability.
Vulnerability is a key risk factor, referring to a weakness that can be exploited by a threat.
NIST SP 800-37 defines risk as a function of the likelihood of a threat source exploiting a vulnerability and the resulting impact. The core risk factors are generally understood as threat, vulnerability, and impact, often combined with likelihood. A 'threat actor' is the entity (human or otherwise) that initiates a threat, not a separate primary risk factor.
Concept tested: NIST risk factors definition
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.