What is the definition of a threat according to ISO/IEC 27000?
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
According to ISO/IEC 27000:2018, Clause 3.74, a threat is defined as:
''Potential cause of an unwanted incident, which can result in harm to a system or organization.''
This definition directly matches option A.
Option B refers to an ''information security incident'' (ISO/IEC 27000:2018, Clause 3.32).
Option C describes a ''vulnerability'' (ISO/IEC 27000:2018, Clause 3.67).
Option D refers to ''residual risk'' (ISO/IEC 27000:2018, Clause 3.61).
The standard emphasizes that threats exploit vulnerabilities, causing incidents that can harm information confidentiality, integrity, and availability. Correctly identifying threats is critical for risk assessment (Clause 6.1.2). Thus, the correct definition per ISO/IEC 27000 is A.
Vilma
3 days agoGayla
8 days agoJina
14 days agoRebeca
19 days agoJesusa
24 days agoViola
29 days agoNoel
1 month agoPhillip
1 month agoZona
1 month agoCassandra
2 months agoEileen
2 months agoLina
2 months agoLuisa
2 months agoElliott
2 months agoVenita
3 months agoSarah
3 months agoAnglea
3 months agoMarci
3 months agoScot
4 months agoJusta
4 months agoJani
3 months agoJaleesa
4 months agoChaya
4 months agoDesmond
4 months agoDominga
5 months ago