nerdexam
CompTIA

CAS-003 · Question #807

The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure:

The correct answer is A. Budgeting for cybersecurity increases year over year. NOTE: The marked answer (A) appears to be incorrect. The primary purpose of a CISO providing up-to-date cybersecurity metrics to a risk committee is to ensure the organization understands the current state of its cybersecurity risk posture - answer D. Risk committees exist…

Risk Management

Question

The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure:

Options

  • ABudgeting for cybersecurity increases year over year.
  • BThe committee knows how much work is being done.
  • CBusiness units are responsible for their own mitigation.
  • DThe bank is aware of the status of cybersecurity risks

How the community answered

(37 responses)
  • A
    89% (33)
  • B
    3% (1)
  • C
    5% (2)
  • D
    3% (1)

Explanation

NOTE: The marked answer (A) appears to be incorrect. The primary purpose of a CISO providing up-to-date cybersecurity metrics to a risk committee is to ensure the organization understands the current state of its cybersecurity risk posture - answer D. Risk committees exist specifically to oversee and govern risk, and they require accurate, current data to fulfill that responsibility. Metrics enable informed decision-making about risk acceptance, mitigation, and transfer. While metrics may indirectly support budget justification (A), that is a secondary outcome, not the primary goal. The correct answer should be D: 'The bank is aware of the status of cybersecurity risks.'

Topics

#security metrics#risk reporting#cybersecurity governance#risk committee

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice