CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A cybersecurity analyst is preparing a vulnerability report for executive leadership. The report needs to clearly articulate the potential business impact of identified critical vulnerabilities. Which of the following metrics would be MOST effective in conveying this information to a non-technical audience?
- AMean Time To Contain (MTTC)
- BCommon Vulnerability Scoring System (CVSS) Base Score
- CNumber of open critical vulnerabilities
- DRisk Likelihood and Business Impact Rating
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Likelihood and Business Impact Rating
For executive leadership, explaining risk in terms of likelihood and business impact provides a clear, non-technical understanding of potential harm, which is more effective than technical scores or raw counts.
Why the other options are wrong
- A. MTTC is an incident response metric, not directly a vulnerability reporting metric for business impact.
- B. CVSS scores are technical and may not be easily understood by non-technical leadership without further context.
- C. While useful, a raw count doesn't convey the *severity* of the business impact for each vulnerability.
Business Impact Rating
A qualitative or quantitative assessment of the potential harm to an organization's operations, assets, or reputation if a specific risk or vulnerability is exploited.
- Focuses on organizational consequences, not technical details.
- Often uses categories like 'High', 'Medium', 'Low' for clarity.
- Essential for communicating risk to non-technical stakeholders.
Memory trick: Executives care about 'Dollars and Disruption', not 'Code and Counts'.