ExamGecko
Question list
Search
Search

Question 503 - CISM discussion

Report
Export

When establishing metrics for an information security program, the BEST approach is to identify indicators that:

A.
reduce information security program spending.
Answers
A.
reduce information security program spending.
B.
support major information security initiatives.
Answers
B.
support major information security initiatives.
C.
reflect the corporate risk culture.
Answers
C.
reflect the corporate risk culture.
D.
demonstrate the effectiveness of the security program.
Answers
D.
demonstrate the effectiveness of the security program.
Suggested answer: D

Explanation:

Metrics for an information security program should be aligned with the security objectives and strategy, and should demonstrate how well the program is performing in terms of reducing risk, enhancing security posture, and supporting business goals. Metrics that support major information security initiatives, reflect the corporate risk culture, or reduce information security program spending may be useful, but they are not the best approach for establishing metrics for the entire program.

Reference= CISM Review Manual 2022, page 3171; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.112

asked 01/10/2024
eddie alvarez
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first