ExamGecko
Question list
Search
Search

Question 545 - CISM discussion

Report
Export

Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?

A.
Information security program metrics
Answers
A.
Information security program metrics
B.
Results of a recent external audit
Answers
B.
Results of a recent external audit
C.
The information security operations matrix
Answers
C.
The information security operations matrix
D.
Changes to information security risks
Answers
D.
Changes to information security risks
Suggested answer: A

Explanation:

Information security program metrics are the best way to demonstrate the status of an organization's information security program to the board of directors, as they provide relevant and meaningful information on the performance, effectiveness, and value of the program, as well as the current and emerging risks and the corresponding mitigation strategies. Information security program metrics should be aligned with the business objectives and risk appetite of the organization, and should be presented in a clear and concise manner that enables the board of directors to make informed decisions and provide oversight. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Mark Anthony Acorda
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first