ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

An organization is conducting a risk assessment for its new cloud-based email system. They identify that a successful phishing attack could lead to a data breach, resulting in regulatory fines and reputational damage. What component of risk is being described by 'regulatory fines and reputational damage'?

  1. AVulnerability
  2. BImpact
  3. CLikelihood
  4. DThreat
Show answer & explanation

Correct answer: B. Impact

Impact refers to the magnitude of harm that could be caused if a threat exploits a vulnerability. Regulatory fines and reputational damage are direct consequences, thus representing the impact.

Why the other options are wrong

  • A. A vulnerability is a weakness that could be exploited, such as a lack of security awareness training, not the outcome.
  • C. Likelihood refers to the probability of a threat exploiting a vulnerability, not the consequence.
  • D. A threat is a potential cause of an undesirable incident, like a phishing attack, not the resulting damage.

Impact (Risk)

The magnitude of harm that can be caused by a security incident or the realization of a risk.

  • Quantifies the damage in terms of financial loss, reputational damage, operational disruption, etc.
  • Used in conjunction with likelihood to determine the overall risk level.
  • Can be qualitative (high, medium, low) or quantitative (monetary value).

Memory trick: Threat finds a Vulnerability, causing an Impact, with some Likelihood.

More Security Principles questions