nerdexam
(ISC)2

CGRC · Question #621

Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. Response:

The correct answer is A. Adequate Security. The term "Adequate Security" describes security measures that are proportionate to the identified risk and the potential harm resulting from the loss, misuse, or unauthorized access to or modification of information. This principle ensures that protection efforts match the signif

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. Response:

Options

  • AAdequate Security
  • BSecurity Category
  • CSecurity Controls
  • DSecurity Categorization

How the community answered

(23 responses)
  • A
    96% (22)
  • B
    4% (1)

Why each option

The term "Adequate Security" describes security measures that are proportionate to the identified risk and the potential harm resulting from the loss, misuse, or unauthorized access to or modification of information. This principle ensures that protection efforts match the significance of the assets being protected.

AAdequate SecurityCorrect

Adequate Security refers to the level of security measures implemented that are appropriate and proportional to the identified risk and the potential magnitude of harm that could result from a breach or compromise of information. It means applying enough security, but not necessarily excessive security, to protect information effectively.

BSecurity Category

Security Category refers to the impact level (low, moderate, high) assigned to an information system based on the potential impact of a breach on confidentiality, integrity, and availability.

CSecurity Controls

Security Controls are the specific safeguards or countermeasures employed to protect the confidentiality, integrity, and availability of information systems.

DSecurity Categorization

Security Categorization is the process of determining the security category for an information system, based on an impact analysis.

Concept tested: Definition of Adequate Security

Source: https://csrc.nist.gov/glossary/term/adequate_security

Topics

#Adequate Security#Risk Management#Security Definitions

Community Discussion

No community discussion yet for this question.

Full CGRC Practice