ExamGecko
Question list
Search
Search

Question 592 - CISM discussion

Report
Export

An organization implemented a number of technical and administrative controls to mitigate risk associated with ransomware. Which of the following is MOST important to present to senior management when reporting on the performance of this initiative?

A.
The cost and associated risk reduction
Answers
A.
The cost and associated risk reduction
B.
Benchmarks of industry peers impacted by ransomware
Answers
B.
Benchmarks of industry peers impacted by ransomware
C.
The number and severity of ransomware incidents
Answers
C.
The number and severity of ransomware incidents
D.
The total cost of the investment
Answers
D.
The total cost of the investment
Suggested answer: A

Explanation:

According to the CISM Review Manual, the most important metric to present to senior management when reporting on the performance of a risk mitigation initiative is the cost and associated risk reduction, as it demonstrates the value and effectiveness of the initiative in terms of reducing the likelihood and impact of the risk. The other metrics may be useful for comparison or analysis, but they do not directly measure the performance of the initiative.

Reference= CISM Review Manual, 27th Edition, Chapter 4, Section 4.3.2, page 2091.

asked 01/10/2024
Matthew Isaacs
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first