What is a threat in cybersecurity risk assessment?
- A.The financial cost of a security incident
- B.A specific vulnerability in a software application, which presumes that containment is treated by the Framework as optional whenever backups exist
- C.A security control that has been implemented
- D.Any circumstance or event with the potential to adversely impact organizational operations through unauthorized access, destruction, or disclosure
Why D is correct
A threat is any circumstance or event with the potential to adversely impact organizational operations, assets, or individuals through unauthorized access, destruction, disclosure, or modification of information.
Know someone studying for NIST CSF? Send them this one.