ExamGecko
Question list
Search
Search

Question 376 - CISM discussion

Report
Export

Which of the following is the MOST important factor in an organization's selection of a key risk indicator (KRI)?

A.
Return on investment (ROI)
Answers
A.
Return on investment (ROI)
B.
Compliance requirements
Answers
B.
Compliance requirements
C.
Target audience
Answers
C.
Target audience
D.
Criticality of information
Answers
D.
Criticality of information
Suggested answer: D

Explanation:

A key risk indicator (KRI) is a metric that provides an early warning of potential exposure to a risk. A KRI should be relevant, measurable, timely, and actionable. The most important factor in an organization's selection of a KRI is the criticality of information, which means that the KRI should reflect the value and sensitivity of the information assets that are exposed to the risk. For example, a KRI for data breach risk could be the number of unauthorized access attempts to a database that contains confidential customer data. The criticality of information helps to prioritize the risks and focus on the most significant ones.

Reference: https://www.isaca.org/credentialing/cism https://www.wiley.com/en-us/CISM+Certified+Information+Security+Manager+Study+Guide-p-9781119801948

asked 01/10/2024
Lin Sun
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first