nerdexam
Isaca

CISM · Question #291

When implementing a SIEM solution to monitor the effectiveness of security controls, which of the following is the MOST important requirement from an information security manager's perspective?

The correct answer is B. Defined thresholds for each security control. Defined thresholds for each security control are the most important requirement because they establish the measurable baseline against which the SIEM determines whether a control is operating within acceptable parameters or has failed. Without defined thresholds, there is no obje

Submitted by ravi_2018· Apr 18, 2026Information Security Program Development and Management

Question

When implementing a SIEM solution to monitor the effectiveness of security controls, which of the following is the MOST important requirement from an information security manager's perspective?

Options

  • ACompatibility with legacy architecture
  • BDefined thresholds for each security control
  • CExtensive ruleset for event consolidation
  • DMaximum available number of log connectors

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    72% (23)
  • C
    16% (5)
  • D
    6% (2)

Explanation

Defined thresholds for each security control are the most important requirement because they establish the measurable baseline against which the SIEM determines whether a control is operating within acceptable parameters or has failed. Without defined thresholds, there is no objective standard to evaluate control effectiveness - the SIEM cannot distinguish normal behavior from a control failure. From the information security manager's perspective, the entire purpose of monitoring is to detect deviations from expected control behavior, which requires those expectations to be formally defined. Compatibility (A), rulesets (C), and log connectors (D) are implementation concerns, but they are meaningless without clear thresholds that define what 'effective' looks like for each control.

Topics

#SIEM#Security Controls#Effectiveness Measurement#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice