QuestionQ15

Human Factors in Security Testing

You have been tasked with conducting the risk assessment for an internal project in your organization. You decide to involve customers, regulatory agencies, or standards that they recommend or mandate.

Which ONE of the following is a type of security threat you are likely to overlook because certain stakeholder types, such as the public/community, were insufficiently involved?

Explanation

Insufficient stakeholder participation can omit perspectives needed to identify insider-related threat sources. Internal threats are a security-threat category, whereas the other statements concern assessment scope, a security principle, or threat likelihood rather than a type of threat.

Community Discussion

No comments yet. Be the first to start the discussion!