nerdexam
(ISC)2

CGRC · Question #715

The potential impact is high if-The loss of confidentiality, integrity, or availability could be expected to have a.......................... Response:

The correct answer is A. severe or catastrophic adverse effect on organizational operations, organizational assets, or. A high potential impact is defined as a severe or catastrophic adverse effect resulting from the loss of confidentiality, integrity, or availability.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The potential impact is high if-The loss of confidentiality, integrity, or availability could be expected to have a.......................... Response:

Options

  • Asevere or catastrophic adverse effect on organizational operations, organizational assets, or
  • Blimited adverse effect on organizational operations, organizational assets, or individuals.
  • Cno adverse effect on organizational operations, organizational assets, or individuals.
  • Dserious adverse effect on organizational operations, organizational assets, or individuals

How the community answered

(50 responses)
  • A
    94% (47)
  • C
    2% (1)
  • D
    4% (2)

Why each option

A high potential impact is defined as a severe or catastrophic adverse effect resulting from the loss of confidentiality, integrity, or availability.

Asevere or catastrophic adverse effect on organizational operations, organizational assets, orCorrect

According to NIST impact levels, a 'high' impact severity rating indicates that the loss of confidentiality, integrity, or availability could result in a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. This level of impact often involves major financial loss, critical mission failure, or severe damage to public confidence.

Blimited adverse effect on organizational operations, organizational assets, or individuals.

A limited adverse effect describes a 'low' impact level.

Cno adverse effect on organizational operations, organizational assets, or individuals.

No adverse effect is not a recognized impact level for security categorization.

Dserious adverse effect on organizational operations, organizational assets, or individuals

A serious adverse effect describes a 'moderate' impact level, which is less severe than high.

Concept tested: Impact levels for security breaches

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Risk impact levels#CIA loss#Adverse effects#Organizational impact

Community Discussion

No community discussion yet for this question.

Full CGRC Practice