ExamGecko
Question list
Search
Search

Question 406 - CISM discussion

Report
Export

Which of the following is the BEST way to determine if an information security profile is aligned with business requirements?

A.
Review the key performance indicator (KPI) dashboard
Answers
A.
Review the key performance indicator (KPI) dashboard
B.
Review security-related key risk indicators (KRIs)
Answers
B.
Review security-related key risk indicators (KRIs)
C.
Review control self-assessment (CSA) results
Answers
C.
Review control self-assessment (CSA) results
D.
Review periodic security audits
Answers
D.
Review periodic security audits
Suggested answer: B

Explanation:

Security-related KRIs are metrics that measure the effectiveness of the information security profile in achieving the business objectives and managing the risks. Reviewing security-related KRIs can help to determine if the information security profile is aligned with business requirements, as they reflect the security performance and outcomes that are relevant for the business. Reviewing other options, such as KPIs, CSAs, or audits, may provide some insights into the security status, but they are not the best way to assess the alignment with business requirements, as they may not capture the business context and goals adequately.

Reference:

https://www.nist.gov/cyberframework/examples-framework-profiles

https://www.isaca.org/resources/isaca-journal/issues/2019/volume-5/accountability-for-information-security-roles-and-responsibilities-part-1

https://www.isaca.org/resources/isaca-journal/issues/2017/volume-4/enterprise-security-architecturea-top-down-approach

asked 01/10/2024
Suraj Porwal
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first