nerdexam
Isaca

CISM · Question #434

Which of the following BEST enables an organization to continuously assess the information security risk posture?

The correct answer is B. Key risk indicators (KRIs). Key risk indicators (KRIs) enable an organization to continuously assess its information security risk posture by providing real-time, measurable data on emerging risks and vulnerabilities. KRIs help detect trends, monitor risk levels, and trigger proactive responses before incid

Submitted by carter_n· Apr 18, 2026Information Security Risk Management

Question

Which of the following BEST enables an organization to continuously assess the information security risk posture?

Options

  • APeriodic review of the risk register
  • BKey risk indicators (KRIs)
  • CDegree of senior management support
  • DCompliance with industry regulations

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    88% (21)
  • D
    4% (1)

Explanation

Key risk indicators (KRIs) enable an organization to continuously assess its information security risk posture by providing real-time, measurable data on emerging risks and vulnerabilities. KRIs help detect trends, monitor risk levels, and trigger proactive responses before incidents occur. While periodic risk register reviews, management support, and regulatory compliance are important, they do not provide continuous monitoring and assessment like KRIs do.

Topics

#Risk Management#Key Risk Indicators#Continuous Monitoring#Risk Posture

Community Discussion

No community discussion yet for this question.

Full CISM Practice