Subject: Security Policy & Procedures
In the context of NIST SP 800-30, define threat and define vulnerability. Give one example of an IT threat and an IT vulnerability.
Answer: According to NIST SP 800-30 a threat can be defined as any circumstance or event with the potential to adversely impact organizational operations and assets, individuals, other organizations, or the Nation through an information system via unauthorized access, disclosure, destruction, or modification of information, and/or denial of service.
Whereas a vulnerability is a weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source.
A prominent example of IT threat can be a provisioning server which is taken offline by a denial-of-service attack, a deliberate act by a malicious system administrator, an administrative error, a hardware fault, or a power failure.
Examples of vulnerability can include
Get Answers For Free
Most questions answered within 1 hours.