GCFA · Question #178
Which of the following NIST RA process steps has the goal to identify the potential threat-sources and compile a threat statement listing the potential threat-sources that are applicable to the IT…
The correct answer is A. Threat Identification. NIST SP 800-30 defines Threat Identification as the specific risk assessment step whose goal is to identify potential threat-sources and produce a threat statement applicable to the IT system being evaluated.
Question
Which of the following NIST RA process steps has the goal to identify the potential threat-sources and compile a threat statement listing the potential threat-sources that are applicable to the IT system being evaluated?
Options
- AThreat Identification
- BVulnerability Identification
- CImpact Analysis
- DControl Analysis
How the community answered
(49 responses)- A71% (35)
- B8% (4)
- C4% (2)
- D16% (8)
Why each option
NIST SP 800-30 defines Threat Identification as the specific risk assessment step whose goal is to identify potential threat-sources and produce a threat statement applicable to the IT system being evaluated.
In the NIST risk assessment methodology, Threat Identification is the step where analysts research and compile all relevant threat-sources - natural, human, and environmental - that could exploit vulnerabilities in the target system. The output is a formal threat statement that documents each applicable source and its motivation or capability. This step precedes vulnerability and control analysis and provides the foundation for subsequent risk calculations.
Vulnerability Identification is the step focused on discovering and cataloging weaknesses in the system itself, not on identifying the external or internal sources of threats.
Impact Analysis assesses the potential adverse consequences to the organization if a threat successfully exploits a vulnerability, occurring after threat and vulnerability identification are complete.
Control Analysis examines current and planned safeguards to determine whether they adequately reduce the likelihood of a threat exploiting a vulnerability, not to enumerate threat-sources.
Concept tested: NIST SP 800-30 risk assessment threat identification step
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.