ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
An organization is conducting a risk assessment for its new cloud-based email system. They identify that a successful phishing attack could lead to a data breach, resulting in regulatory fines and reputational damage. What component of risk is being described by 'regulatory fines and reputational damage'?
- AVulnerability
- BImpact
- CLikelihood
- DThreat
Show answer & explanationAnswer & explanation
Correct answer: B. Impact
Impact refers to the magnitude of harm that could be caused if a threat exploits a vulnerability. Regulatory fines and reputational damage are direct consequences, thus representing the impact.
Why the other options are wrong
- A. A vulnerability is a weakness that could be exploited, such as a lack of security awareness training, not the outcome.
- C. Likelihood refers to the probability of a threat exploiting a vulnerability, not the consequence.
- D. A threat is a potential cause of an undesirable incident, like a phishing attack, not the resulting damage.
Impact (Risk)
The magnitude of harm that can be caused by a security incident or the realization of a risk.
- Quantifies the damage in terms of financial loss, reputational damage, operational disruption, etc.
- Used in conjunction with likelihood to determine the overall risk level.
- Can be qualitative (high, medium, low) or quantitative (monetary value).
Memory trick: Threat finds a Vulnerability, causing an Impact, with some Likelihood.