ExamGecko
Question list
Search
Search

Question 561 - CISM discussion

Report
Export

Which of the following should be the PRIMARY basis for establishing metrics that measure the effectiveness of an information security program?

A.
Residual risk
Answers
A.
Residual risk
B.
Regulatory requirements
Answers
B.
Regulatory requirements
C.
Risk tolerance
Answers
C.
Risk tolerance
D.
Control objectives
Answers
D.
Control objectives
Suggested answer: C

Explanation:

The primary basis for establishing metrics that measure the effectiveness of an information security program should be the risk tolerance of the organization, which is the degree of risk that the organization is willing to accept or avoid in pursuit of its objectives. Metrics based on risk tolerance can help to evaluate whether the information security program is aligned with the business strategy, supports the risk management process, and delivers value to the organization. Residual risk, regulatory requirements, and control objectives are also important factors to consider when developing metrics, but they are not as fundamental as the risk tolerance.

Reference= CISM Review Manual, 16th Edition, page 69

asked 01/10/2024
João Faria
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first