CISA · Question #218
Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization's cybersecurity posture?
The correct answer is D. Maturity assessment results. A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a…
Question
Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization’s cybersecurity posture?
Options
- AVulnerability assessment results
- BIncident response metrics
- CInternal audit findings
- DMaturity assessment results
How the community answered
(58 responses)- A5% (3)
- B16% (9)
- C9% (5)
- D71% (41)
Explanation
A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a multi-dimensional view of current state and gaps. Vulnerability assessments (A) are point-in-time technical scans. Incident response metrics (B) reflect only one capability domain. Internal audit findings (C) are also point-in-time and scope-limited. Only a maturity assessment provides the breadth and depth needed for a comprehensive posture evaluation.
Topics
Community Discussion
No community discussion yet for this question.