ExamGecko
Question list
Search
Search

Question 44 - CISM discussion

Report
Export

In order to understand an organization's security posture, it is MOST important for an organization's senior leadership to:

A.
evaluate results of the most recent incident response test.
Answers
A.
evaluate results of the most recent incident response test.
B.
review the number of reported security incidents.
Answers
B.
review the number of reported security incidents.
C.
ensure established security metrics are reported.
Answers
C.
ensure established security metrics are reported.
D.
assess progress of risk mitigation efforts.
Answers
D.
assess progress of risk mitigation efforts.
Suggested answer: D

Explanation:

According to the CISM Review Manual, an organization's security posture is the overall condition of its information security, which is determined by the effectiveness of its security program and the alignment of its security objectives with its business goals. To understand the security posture, the senior leadership needs to have a holistic view of the security risks and the actions taken to address them. Therefore, assessing the progress of risk mitigation efforts is the most important activity for the senior leadership, as it provides them with the information on how well the security program is performing and whether it is meeting the expected outcomes. Evaluating the results of the most recent incident response test, reviewing the number of reported security incidents, and ensuring established security metrics are reported are all useful activities for the senior leadership, but they are not sufficient to understand the security posture. They only provide partial or isolated information on the security performance, which may not reflect the overall security condition or the alignment with the business objectives.Reference= CISM Review Manual, 16th Edition, Chapter 1, Information Security Governance, pages 28-29.

asked 01/10/2024
Tim baxter
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first