CISM · Question #2
When establishing metrics for an information security program, the BEST approach is to identify indicators that:
The correct answer is D. demonstrate the effectiveness of the security program. The best approach to establishing information security metrics is to identify indicators that clearly demonstrate the overall effectiveness of the security program.
Question
When establishing metrics for an information security program, the BEST approach is to identify indicators that:
Options
- Asupport major information security initiatives.
- Breflect the corporate risk culture.
- Creduce information security program spending.
- Ddemonstrate the effectiveness of the security program.
How the community answered
(34 responses)- B3% (1)
- C3% (1)
- D94% (32)
Why each option
The best approach to establishing information security metrics is to identify indicators that clearly demonstrate the overall effectiveness of the security program.
While supporting major initiatives is a good outcome, it's a subset of demonstrating overall program effectiveness and not the primary focus for all metrics.
Reflecting corporate risk culture is important for alignment, but metrics should go beyond culture to objectively measure security performance.
Reducing program spending might be a goal, but it's not the primary purpose of security metrics, which should focus on security posture and effectiveness.
Metrics should primarily measure how well the security program achieves its objectives, such as reducing risk, protecting assets, and ensuring compliance, thereby demonstrating its effectiveness to stakeholders. This allows for data-driven decision-making and continuous improvement of security controls and strategies.
Concept tested: Information security program metrics
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-55r1.pdf
Topics
Community Discussion
No community discussion yet for this question.