What is the definition of a threat according to ISO/IEC 27000?
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
According to ISO/IEC 27000:2018, Clause 3.74, a threat is defined as:
''Potential cause of an unwanted incident, which can result in harm to a system or organization.''
This definition directly matches option A.
Option B refers to an ''information security incident'' (ISO/IEC 27000:2018, Clause 3.32).
Option C describes a ''vulnerability'' (ISO/IEC 27000:2018, Clause 3.67).
Option D refers to ''residual risk'' (ISO/IEC 27000:2018, Clause 3.61).
The standard emphasizes that threats exploit vulnerabilities, causing incidents that can harm information confidentiality, integrity, and availability. Correctly identifying threats is critical for risk assessment (Clause 6.1.2). Thus, the correct definition per ISO/IEC 27000 is A.
Dallas
6 months agoVilma
6 months agoGayla
6 months agoJina
7 months agoRebeca
7 months agoJesusa
7 months agoViola
7 months agoNoel
7 months agoPhillip
7 months agoZona
8 months agoCassandra
8 months agoEileen
8 months agoLina
8 months agoLuisa
8 months agoElliott
9 months agoVenita
9 months agoSarah
9 months agoAnglea
9 months agoMarci
10 months agoScot
10 months agoJusta
10 months agoLoreta
5 months agoJohnetta
5 months agoRickie
5 months agoJani
9 months agoJaleesa
10 months agoChaya
10 months agoDesmond
11 months agoDominga
11 months ago