CISM · Question #265
Which of the following provides the BEST evidence that a security program is mature?
The correct answer is C. Controls are implemented based on risk assessment results. A risk assessment-driven control selection process is the hallmark of a mature security program because it is proactive, systematic, and business-aligned. Mature programs identify and prioritize risks before controls are selected, ensuring resources are applied where they…
Question
Which of the following provides the BEST evidence that a security program is mature?
Options
- AControls are implemented based on vulnerability assessment results.
- BControls are implemented based on root cause analysis of incidents.
- CControls are implemented based on risk assessment results.
- DControls are implemented based on security audit findings.
How the community answered
(29 responses)- A3% (1)
- B14% (4)
- C79% (23)
- D3% (1)
Explanation
A risk assessment-driven control selection process is the hallmark of a mature security program because it is proactive, systematic, and business-aligned. Mature programs identify and prioritize risks before controls are selected, ensuring resources are applied where they reduce the most risk. Controls driven by vulnerability assessments (A) are technically reactive and narrow in scope. Controls driven by root cause analysis of incidents (B) are purely reactive - waiting for harm before acting. Controls driven by audit findings (D) are compliance-oriented and backward-looking. Only risk assessment-driven controls reflect the forward-looking, proportional, and strategic decision-making that characterizes program maturity.
Topics
Community Discussion
No community discussion yet for this question.