ExamGecko
Question list
Search
Search

Question 655 - CISM discussion

Report
Export

What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?

A.
Developing a dashboard for communicating the metrics
Answers
A.
Developing a dashboard for communicating the metrics
B.
Agreeing on baseline values for the metrics
Answers
B.
Agreeing on baseline values for the metrics
C.
Benchmarking the expected value of the metrics against industry standards
Answers
C.
Benchmarking the expected value of the metrics against industry standards
D.
Aligning the metrics with the organizational culture
Answers
D.
Aligning the metrics with the organizational culture
Suggested answer: D

Explanation:

The most important consideration when establishing metrics for reporting to the information security strategy committee is D. Aligning the metrics with the organizational culture. This is because the metrics should reflect the values, beliefs, and behaviors of the organization and its stakeholders, and support the achievement of the strategic objectives and goals. The metrics should also be relevant, meaningful, and understandable for the intended audience, and provide clear and actionable information for decision making. The metrics should not be too technical, complex, or ambiguous, but rather focus on the key aspects of information security performance, such as risk, compliance, maturity, value, and effectiveness.

Reference = CISM Review Manual 15th Edition, Chapter 1, Section 1.3.2, page 281; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 5, page 3

asked 01/10/2024
Mekmek Kh
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first