CISM · Question #118
When determining key risk indicators (KRIs) for use in an information security program it is MOST important to select:
The correct answer is B. KRIs that align with business processes. Key risk indicators must primarily align with business processes to provide meaningful insights into risks that directly impact organizational objectives.
Question
When determining key risk indicators (KRIs) for use in an information security program it is MOST important to select:
Options
- AKRIs that track both short-term and long-term performance.
- BKRIs that align with business processes.
- CKRIs that are quantifiable.
- Das many KRIs as possible to catch risk events from the broadest areas.
How the community answered
(56 responses)- A7% (4)
- B73% (41)
- C16% (9)
- D4% (2)
Why each option
Key risk indicators must primarily align with business processes to provide meaningful insights into risks that directly impact organizational objectives.
While tracking both short-term and long-term performance is good, it's secondary to ensuring the KRIs are fundamentally relevant to the business.
For KRIs to be truly valuable, they must directly relate to and provide early warning signs for risks that could impact the organization's critical business processes and strategic objectives. Aligning KRIs with business processes ensures that risk monitoring is relevant and actionable from a business perspective.
Quantifiability is a characteristic of a *good* KRI, but the *most important* aspect is its relevance and alignment with what the business values.
Selecting too many KRIs can lead to "indicator fatigue" and diminish the focus on truly critical risks; quality and relevance are more important than quantity.
Concept tested: Key Risk Indicator (KRI) selection
Topics
Community Discussion
No community discussion yet for this question.