ExamGecko
Question list
Search
Search

Question 330 - CISM discussion

Report
Export

Which of the following metrics provides the BEST evidence of alignment of information security governance with corporate governance?

A.
Average return on investment (ROI) associated with security initiatives
Answers
A.
Average return on investment (ROI) associated with security initiatives
B.
Average number of security incidents across business units
Answers
B.
Average number of security incidents across business units
C.
Mean time to resolution (MTTR) for enterprise-wide security incidents
Answers
C.
Mean time to resolution (MTTR) for enterprise-wide security incidents
D.
Number of vulnerabilities identified for high-risk information assets
Answers
D.
Number of vulnerabilities identified for high-risk information assets
Suggested answer: A

Explanation:

Average return on investment (ROI) associated with security initiatives is the best metric to provide evidence of alignment of information security governance with corporate governance because it demonstrates the value and benefits of security investments to the organization's strategic goals and objectives. Average number of security incidents across business units is not a good metric because it does not measure the effectiveness or efficiency of security initiatives or their alignment with corporate governance. Mean time to resolution (MTTR) for enterprise-wide security incidents is not a good metric because it does not measure the impact or outcome of security initiatives or their alignment with corporate governance. Number of vulnerabilities identified for high-risk information assets is not a good metric because it does not measure the performance or improvement of security initiatives or their alignment with corporate governance.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2015/volume-6/measuring-the-value-of-information-security-investments https://www.isaca.org/resources/isaca-journal/issues/2015/volume-1/how-to-measure-the-effectiveness-of-information-security-governance

asked 01/10/2024
Amidou Florian TOURE
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first