Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium
A security team is evaluating the risk of an insider threat stealing sensitive intellectual property. They estimate the probability of such an event occurring in a year is 0.01 (or 1%). The financial loss if this happens is estimated to be $10,000,000, and the reputational damage, though hard to quantify, is considered 'Catastrophic'. What component of the risk assessment is primarily being focused on when considering the 'Catastrophic' reputational damage?
- AAsset Value (AV)
- BImpact
- CExposure Factor (EF)
- DAnnualized Rate of Occurrence (ARO)
Show answer & explanationAnswer & explanation
Correct answer: B. Impact
The 'Catastrophic' reputational damage directly describes the consequence or severity of the insider threat event, which is a key component of assessing the impact of a risk. While financial loss is also impact, 'Catastrophic' specifically refers to the qualitative severity.
Why the other options are wrong
- A. Asset Value (AV) refers to the financial worth of the intellectual property itself, not the damage incurred.
- C. Exposure Factor (EF) is a percentage of asset value lost, used to calculate SLE, but 'Catastrophic' is a direct descriptor of consequences.
- D. Annualized Rate of Occurrence (ARO) is the 0.01 probability mentioned, not the damage.
Risk Impact
The magnitude of harm or loss that would result if a risk event occurs, often assessed in terms of financial, operational, or reputational consequences.
- Can be qualitative (e.g., Low, Medium, High) or quantitative (e.g., monetary value).
- One of two primary factors in determining overall risk level (with likelihood).
- Considers direct and indirect consequences.
Memory trick: Threats exploit Vulnerabilities, hitting Assets, causing Impact and Likelihood.