ExamGecko
Question list
Search
Search

Question 527 - CISM discussion

Report
Export

Which of the following is the MOST appropriate metric to demonstrate the effectiveness of information security controls to senior management?

A.
Downtime due to malware infections
Answers
A.
Downtime due to malware infections
B.
Number of security vulnerabilities uncovered with network scans
Answers
B.
Number of security vulnerabilities uncovered with network scans
C.
Percentage of servers patched
Answers
C.
Percentage of servers patched
D.
Annualized loss resulting from security incidents
Answers
D.
Annualized loss resulting from security incidents
Suggested answer: D

Explanation:

Annualized loss resulting from security incidents is the most appropriate metric to demonstrate the effectiveness of information security controls to senior management, as it quantifies the financial impact of security breaches on the organization's assets, operations, and reputation. This metric helps to communicate the value of security investments, justify the security budget, and prioritize the security initiatives based on the potential loss reduction. Annualized loss resulting from security incidents can be calculated by multiplying the annualized rate of occurrence (ARO) of an incident by the single loss expectancy (SLE) of an incident. ARO is the estimated frequency of an incident occurring in a year, and SLE is the estimated cost of an incident. For example, if an organization estimates that a ransomware attack may occur once every two years, and that each attack may cost $100,000 to recover, then the annualized loss resulting from ransomware attacks is $50,000 ($100,000 / 2).

Reference= CISM Review Manual 2022, page 3171; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.112;Key Performance Indicators for Security Governance, Part 1;Performance Measurement Guide for Information Security

asked 01/10/2024
Mina Shaker
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first