CGRC · Question #63
Not all deficiencies in controls or lack of security protections are vulnerabilities. Vulnerabilities in control can be defined as: Response:
The correct answer is A. Only deficiencies that can be explioted. A vulnerability is specifically a deficiency in a control or lack of security protection that can be exploited by a threat to cause harm.
Question
Not all deficiencies in controls or lack of security protections are vulnerabilities. Vulnerabilities in control can be defined as:
Response:
Options
- AOnly deficiencies that can be explioted
- BMissing patches
- CAll deficiencies in the controls
- DAcceptable risks to the organization
How the community answered
(66 responses)- A91% (60)
- B2% (1)
- C3% (2)
- D5% (3)
Why each option
A vulnerability is specifically a deficiency in a control or lack of security protection that can be exploited by a threat to cause harm.
A vulnerability is defined as a weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source. Simply having a deficiency is not enough; for it to be a vulnerability, it must present a potential pathway for exploitation.
Missing patches are a type of vulnerability, but the definition of a vulnerability is broader than just missing patches.
Not all deficiencies are vulnerabilities; a deficiency must be exploitable to be considered a vulnerability in the context of security.
Acceptable risks are the risks an organization is willing to tolerate, which is a risk management decision, not a definition of a vulnerability itself.
Concept tested: Definition of vulnerability
Source: https://csrc.nist.gov/glossary/term/vulnerability
Topics
Community Discussion
No community discussion yet for this question.