CAS-003 · Question #807
The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure:
The correct answer is A. Budgeting for cybersecurity increases year over year. NOTE: The marked answer (A) appears to be incorrect. The primary purpose of a CISO providing up-to-date cybersecurity metrics to a risk committee is to ensure the organization understands the current state of its cybersecurity risk posture - answer D. Risk committees exist…
Question
The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure:
Options
- ABudgeting for cybersecurity increases year over year.
- BThe committee knows how much work is being done.
- CBusiness units are responsible for their own mitigation.
- DThe bank is aware of the status of cybersecurity risks
How the community answered
(37 responses)- A89% (33)
- B3% (1)
- C5% (2)
- D3% (1)
Explanation
NOTE: The marked answer (A) appears to be incorrect. The primary purpose of a CISO providing up-to-date cybersecurity metrics to a risk committee is to ensure the organization understands the current state of its cybersecurity risk posture - answer D. Risk committees exist specifically to oversee and govern risk, and they require accurate, current data to fulfill that responsibility. Metrics enable informed decision-making about risk acceptance, mitigation, and transfer. While metrics may indirectly support budget justification (A), that is a secondary outcome, not the primary goal. The correct answer should be D: 'The bank is aware of the status of cybersecurity risks.'
Topics
Community Discussion
No community discussion yet for this question.