- Home
- All questions
- Question 105
CISSP study material · question 105 of 500
An assessor insists on pairing every catalogued threat with every catalogued vulnerability before estimating likelihood. What does NIST SP 800-30 say about this practice?
Show the answer
Answer: C. It scales badly and forces excessive detail; threat scenarios at business-function level are preferred.
One-to-one threat-vulnerability pairing is described as undesirable at business-function level and often problematic even at system level, because the number of pairs drives detail rather than insight.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Likelihood