QuestionQ3

Security Operation

Which group is most likely to be the source of an asset loss resulting from the improper or inappropriate use of computers?

  • A Visitors
  • B Customers
  • C Employees
  • D Hackers
Explanation

Employees are considered the most probable source of asset loss from computer misuse because they already possess authorized access to organizational systems, applications, and data. This inherent trust and access level makes it easier for employees—whether through negligence, error, or intentional misconduct—to cause loss of confidentiality, integrity, or availability of assets, compared to outsiders (hackers), who must first overcome external defenses to gain access, or visitors and customers, who typically have minimal or no direct access to internal computing resources. Security risk models used in frameworks such as CISSP's asset security domain emphasize that insider threats, including employees, represent the largest and most consistent risk category for asset loss due to inappropriate computer use.

Community Discussion

No comments yet. Be the first to start the discussion!