You are undertaking a qualitative risk assessment of a likely security threat to an information system. What is the MAIN issue with this type of risk assessment?
- These risk assessments are largely subjective and require agreement on rankings beforehand.
- Dealing with statistical and other numeric data can often be hard to interpret.
- There needs to be a large amount of previous data to "train" a qualitative risk methodology.
- It requires the use of complex software tools to undertake this risk assessment.
Reveal Solution Next Question