Study. uk . com
  1. Home
  2. All questions
  3. Question 106

CISSP study material · question 106 of 500

The same missing patch is rated critical on an internet-facing payment gateway and low on an isolated laboratory host. A reviewer objects that a vulnerability should have one severity. What does NIST SP 800-30 say?

  1. Severity is judged by the harm exploitation would cause, so it is context-dependent.
  2. Severity is fixed by the vulnerability's published score and must not be adjusted.
  3. Severity is a property of the threat source rather than of the weakness.
  4. Severity applies only to the system with the highest impact categorisation.
Show the answer

Answer: A. Severity is judged by the harm exploitation would cause, so it is context-dependent.

SP 800-30 defines vulnerability severity by the extent of the potential adverse impact if exploited, which makes it dependent on the context the weakness sits in.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 footnote 25

Challenge yourself on this topic → Study as cards