ExamGecko
Question list
Search
Search

Question 243 - CISM discussion

Report
Export

The fundamental purpose of establishing security metrics is to:

A.
increase return on investment (ROI)
Answers
A.
increase return on investment (ROI)
B.
provide feedback on control effectiveness
Answers
B.
provide feedback on control effectiveness
C.
adopt security best practices
Answers
C.
adopt security best practices
D.
establish security benchmarks
Answers
D.
establish security benchmarks
Suggested answer: B

Explanation:

The fundamental purpose of establishing security metrics is to provide feedback on the effectiveness of the information security controls and processes. Security metrics are quantitative or qualitative measures that indicate how well the organization is achieving its security objectives and goals. Security metrics can help the information security manager to monitor, evaluate, and improve the performance of the information security program, as well as to identify gaps, weaknesses, and areas for improvement. Security metrics can also help the organization to demonstrate compliance with internal and external standards, regulations, and best practices.Increasing return on investment (ROI), adopting security best practices, and establishing security benchmarks are possible outcomes or benefits of using security metrics, but they are not the fundamental purpose of establishing them.Reference= CISM Review Manual, 16th Edition, pages 46-471; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 642

Learn more:

1. isaca.org2. amazon.com3. gov.uk

Security metrics are used to measure the effectiveness of controls and evaluate the overall security posture of an organization. This feedback provides an understanding of the progress made towards achieving security objectives and allows organizations to make necessary adjustments.

asked 01/10/2024
Sander Verheijen
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first