ExamGecko
Question list
Search
Search

Related questions

Question 281 - CISA discussion

Report
Export

Which of the following is the BEST indicator of the effectiveness of an organization's incident response program?

A.
Number of successful penetration tests
Answers
A.
Number of successful penetration tests
B.
Percentage of protected business applications
Answers
B.
Percentage of protected business applications
C.
Financial impact per security event
Answers
C.
Financial impact per security event
D.
Number of security vulnerability patches
Answers
D.
Number of security vulnerability patches
Suggested answer: C

Explanation:

The best indicator of the effectiveness of an organization's incident response program is the financial impact per security event. This metric measures the direct and indirect costs associated with security incidents, such as loss of revenue, reputation damage, legal fees, recovery expenses, and fines. By reducing the financial impact per security event, the organization can demonstrate that its incident response program is effective in mitigating the consequences of security breaches and restoring normal operations as quickly as possible. Number of successful penetration tests, percentage of protected business applications, and number of security vulnerability patches are indicators of the security posture of the organization, but they do not reflect the effectiveness of the incident response program.Reference:ISACA Journal Article: Measuring Incident Response Effectiveness

asked 18/09/2024
Tuan Nguyen
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first