CISA · Question #218
Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization's cybersecurity posture?
The correct answer is D. Maturity assessment results. A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a multi-dimensional
Question
Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization’s cybersecurity posture?
Options
- AVulnerability assessment results
- BIncident response metrics
- CInternal audit findings
- DMaturity assessment results
How the community answered
(58 responses)- A5% (3)
- B16% (9)
- C9% (5)
- D71% (41)
Explanation
A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a multi-dimensional view of current state and gaps. Vulnerability assessments (A) are point-in-time technical scans. Incident response metrics (B) reflect only one capability domain. Internal audit findings (C) are also point-in-time and scope-limited. Only a maturity assessment provides the breadth and depth needed for a comprehensive posture evaluation.
Topics
Community Discussion
No community discussion yet for this question.