ExamGecko
Question list
Search
Search

Question 173 - CISM discussion

Report
Export

Which of the following is MOST important to include in monthly information security reports to the board?

A.
Trend analysis of security metrics
Answers
A.
Trend analysis of security metrics
B.
Risk assessment results
Answers
B.
Risk assessment results
C.
Root cause analysis of security incidents
Answers
C.
Root cause analysis of security incidents
D.
Threat intelligence
Answers
D.
Threat intelligence
Suggested answer: A

Explanation:

The most important information to include in monthly information security reports to the board is the trend analysis of security metrics. Security metrics are quantitative and qualitative measures that indicate the performance and effectiveness of the information security program and the alignment with the business objectives. Trend analysis is the process of comparing and evaluating the changes and patterns of security metrics over time. Trend analysis can help to identify the strengths and weaknesses of the information security program, the progress and achievements of the security goals and initiatives, the gaps and opportunities for improvement, and the impact and value of the information security investments. Trend analysis can also help to communicate the current and future security risks and challenges, and the recommended actions and strategies to address them. Trend analysis can provide the board with a clear and concise overview of the information security status and direction, and enable informed and timely decision making.

Reference=

CISM Review Manual 15th Edition, page 1631

The CISO's Guide to Reporting Cybersecurity to the Board2

CISM 2020: Information Security Metrics and Reporting, video 13

asked 01/10/2024
Enrique Jose Lopez Bolivar
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first