The library board wants a one-line risk definition the civic SOC can reuse when reviewing malware notables. Which definition should the analyst give?
Select an answer to reveal the explanation.
Short Explanation
Think of risk like a storm hitting a leaky roof over a rare book room—you need a storm (threat), a leak (vulnerability), and something that actually matters if it gets wet (impact or likelihood). A lone malware notable is just weather on the radar, not the whole risk equation.
Full Explanation
Basic risk management treats risk as the combination of a threat, a vulnerability that threat can exploit, and the impact or likelihood of harm if it succeeds. Enterprise Security notables are inputs to that judgment, not a definition of risk by themselves. Counting fired searches or listing hardware replacement cost omits the threat-vulnerability-impact relationship the library board asked for.