- Home
- All questions
- Question 93
CISSP study material · question 93 of 500
An assessment team reports that the organisation has no vulnerabilities because every system passed its scans. The risk executive disagrees. On what grounds, according to NIST SP 800-39?
Show the answer
Answer: D. Vulnerabilities also exist in governance, processes, architecture, facilities, supply chains and external providers.
SP 800-39 places vulnerabilities well beyond technology, in governance structures, business processes, architectures, facilities, life cycle processes, supply chains and external providers.
Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.1 footnote 14