Study. uk . com
  1. Home
  2. All questions
  3. Question 105

CISSP study material · question 105 of 500

An assessor insists on pairing every catalogued threat with every catalogued vulnerability before estimating likelihood. What does NIST SP 800-30 say about this practice?

  1. It is acceptable only where the assessment approach is quantitative.
  2. It is mandatory at Tier 3 and optional at Tiers 1 and 2.
  3. It scales badly and forces excessive detail; threat scenarios at business-function level are preferred.
  4. It is the only way to satisfy the reproducibility requirement.
Show the answer

Answer: C. It scales badly and forces excessive detail; threat scenarios at business-function level are preferred.

One-to-one threat-vulnerability pairing is described as undesirable at business-function level and often problematic even at system level, because the number of pairs drives detail rather than insight.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Likelihood

Challenge yourself on this topic → Study as cards