CISM · Question #257
Which of the following is the MOST important characteristic of an effective information security metric?
The correct answer is A. The metric expresses residual risk relative to risk tolerance. The most important characteristic of a security metric is that it conveys actionable, decision-relevant information. Expressing residual risk (the risk remaining after controls are applied) relative to risk tolerance directly answers the question executives care about most…
Question
Which of the following is the MOST important characteristic of an effective information security metric?
Options
- AThe metric expresses residual risk relative to risk tolerance.
- BThe metric is frequently reported to senior management.
- CThe metric directly maps to an industry risk management framework.
- DThe metric compares the organization's inherent risk against its risk appetite.
How the community answered
(22 responses)- A77% (17)
- B5% (1)
- C14% (3)
- D5% (1)
Explanation
The most important characteristic of a security metric is that it conveys actionable, decision-relevant information. Expressing residual risk (the risk remaining after controls are applied) relative to risk tolerance directly answers the question executives care about most: 'Are we within acceptable risk limits?' Reporting frequency (B) is a delivery characteristic, not a quality characteristic. Mapping to an industry framework (C) aids comparability but is not inherently meaningful without organizational context. Comparing inherent risk to risk appetite (D) ignores the effect of existing controls, making it less meaningful than residual risk, which reflects actual exposure.
Topics
Community Discussion
No community discussion yet for this question.