Study. uk . com
  1. Home
  2. All questions
  3. Question 20

CISSP study material · question 20 of 500

A system owner is documenting, for each security objective, the kinds of compromise that could damage the mission. A colleague has written down only theft of data by an outsider. Which additional forms of compromise does the federal categorisation standard count? Choose three.

  1. Aggregation of the information across separate systems
  2. Disruption of access to the information held
  3. Destruction of the information held by the system
  4. Unauthorised modification of the information held
Show the answer

Answer: C. Destruction of the information held by the system
D. Unauthorised modification of the information held
B. Disruption of access to the information held

The standard counts destruction, disruption, modification, disclosure, unauthorised use and unauthorised access; aggregation is an inference and privacy concern, never one of the listed compromise forms.

Source: NIST FIPS 199 (NIST) — FIPS 199 > Abstract

Challenge yourself on this topic → Study as cards