ExamGecko
Question list
Search
Search

Question 384 - CISM discussion

Report
Export

Which of the following is BEST used to determine the maturity of an information security program?

A.
Security budget allocation
Answers
A.
Security budget allocation
B.
Organizational risk appetite
Answers
B.
Organizational risk appetite
C.
Risk assessment results
Answers
C.
Risk assessment results
D.
Security metrics
Answers
D.
Security metrics
Suggested answer: D

Explanation:

Security metrics are the best way to determine the maturity of an information security program because they are quantifiable indicators of the performance and effectiveness of the security controls and processes. Security metrics help to evaluate the current state of security, identify gaps and weaknesses, measure progress and improvement, and communicate the value and impact of security to stakeholders. Therefore, security metrics are the correct answer.

https://www.isaca.org/resources/isaca-journal/issues/2020/volume-6/key-performance-indicators-for-security-governance-part-1

https://www.gartner.com/en/publications/protect-your-business-assets-with-roadmap-for-maturing-information-security

asked 01/10/2024
mohammed rafiuddin
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first