Assess a control by naming how it could fail, not just whether it exists.
Why this matters NIST SP 800-30 emphasizes threat sources, vulnerabilities, predisposing conditions, likelihood, and impact. In everyday business risk assessment, that means a control is not a magic shield. It is a mechanism that can fail because of design gaps, workload, incentives, access, poor evidence, or weak monitoring. The useful question is not "Do we have a control?" but "What pathway remains if this control is bypassed, overloaded, misunderstood, or misused?" This shifts assessment from checklist compliance to residual risk. A control that depends on a rushed human approving 80 requests a day is different from a control that blocks…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in