Study. uk . com
  1. Home
  2. All questions
  3. Question 93

CISSP study material · question 93 of 500

An assessment team reports that the organisation has no vulnerabilities because every system passed its scans. The risk executive disagrees. On what grounds, according to NIST SP 800-39?

  1. A vulnerability is only closed once the vendor withdraws the affected version.
  2. Scanners cannot detect vulnerabilities that have no published identifier.
  3. Scan results are valid only for systems categorised at moderate impact or above.
  4. Vulnerabilities also exist in governance, processes, architecture, facilities, supply chains and external providers.
Show the answer

Answer: D. Vulnerabilities also exist in governance, processes, architecture, facilities, supply chains and external providers.

SP 800-39 places vulnerabilities well beyond technology, in governance structures, business processes, architectures, facilities, life cycle processes, supply chains and external providers.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.1 footnote 14

Challenge yourself on this topic → Study as cards