CISM · Question #101
The PRIMARY reason for senior management to monitor information security metrics is to ensure:
The correct answer is B. alignment of information security with corporate governance.. Senior management monitors information security metrics primarily to ensure that security efforts are aligned with and support the organization's overall corporate governance objectives.
Question
The PRIMARY reason for senior management to monitor information security metrics is to ensure:
Options
- Aalignment of the information security budget to corporate funding.
- Balignment of information security with corporate governance.
- Calignment of security and IT objectives.
- Dalignment with risk mitigation efforts.
How the community answered
(47 responses)- A2% (1)
- B94% (44)
- C4% (2)
Why each option
Senior management monitors information security metrics primarily to ensure that security efforts are aligned with and support the organization's overall corporate governance objectives.
Aligning the security budget to corporate funding is a financial management task, a subset of broader corporate governance, not the primary reason for monitoring security performance.
Senior management's primary reason for monitoring information security metrics is to ensure alignment of information security with corporate governance, demonstrating due diligence and accountability in managing enterprise risks. Metrics provide a quantifiable way for management to assess if security investments and initiatives are effectively supporting strategic business goals and regulatory compliance.
Alignment of security and IT objectives is important, but corporate governance encompasses a broader organizational view beyond just IT operations.
Alignment with risk mitigation efforts is a core function of security, but the *reason* senior management monitors it is to ensure these efforts are compliant and contribute to overall governance and strategic objectives.
Concept tested: Information security governance and metrics
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001
Topics
Community Discussion
No community discussion yet for this question.