CompTIA CySA+ (CS0-003)Reporting and CommunicationHard

A security analyst is reviewing a vulnerability scan report for a critical database server. The report indicates several 'High' severity vulnerabilities with a CVSS base score range of 7.0-8.9. The analyst knows that the database contains highly sensitive customer data and is directly accessible from the internet. When preparing the vulnerability report for the database owner, which additional detail should the analyst emphasize to BEST convey the true organizational risk beyond the technical CVSS score?

  1. AThe history of past vulnerabilities on similar database systems.
  2. BThe specific CVE IDs associated with each vulnerability.
  3. CThe potential impact on data confidentiality, integrity, and availability (CIA) and regulatory fines.
  4. DThe number of patches required to fix the vulnerabilities.
Show answer & explanation

Correct answer: C. The potential impact on data confidentiality, integrity, and availability (CIA) and regulatory fines.

While CVSS provides a technical severity, conveying the potential impact on CIA (Confidentiality, Integrity, Availability) and the resulting business consequences (like regulatory fines) translates the technical risk into terms that resonate with business owners and highlight the true organizational risk.

Why the other options are wrong

  • A. Historical data is useful for context but doesn't directly convey the *current* organizational risk of these specific vulnerabilities.
  • B. CVE IDs are technical identifiers for specific vulnerabilities, not a measure of organizational risk for the business owner.
  • D. The number of patches is a technical detail for remediation, not a measure of organizational risk.

Organizational Risk Communication

The process of translating technical cybersecurity findings into terms that articulate potential business consequences, such as financial loss, reputational damage, operational disruption, and regulatory penalties.

  • Focuses on 'why it matters' to the business.
  • Uses metrics like financial impact, regulatory fines, and CIA triad implications.
  • Essential for gaining buy-in and resources from business stakeholders.

Memory trick: Beyond 'CVE numbers', focus on 'Cash, Confidentiality, and Compliance'.

More Reporting and Communication questions