- Home
- All questions
- Question 106
CISSP study material · question 106 of 500
The same missing patch is rated critical on an internet-facing payment gateway and low on an isolated laboratory host. A reviewer objects that a vulnerability should have one severity. What does NIST SP 800-30 say?
Show the answer
Answer: A. Severity is judged by the harm exploitation would cause, so it is context-dependent.
SP 800-30 defines vulnerability severity by the extent of the potential adverse impact if exploited, which makes it dependent on the context the weakness sits in.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 footnote 25