CISM · Question #434
Which of the following BEST enables an organization to continuously assess the information security risk posture?
The correct answer is B. Key risk indicators (KRIs). Key risk indicators (KRIs) enable an organization to continuously assess its information security risk posture by providing real-time, measurable data on emerging risks and vulnerabilities. KRIs help detect trends, monitor risk levels, and trigger proactive responses before incid
Question
Which of the following BEST enables an organization to continuously assess the information security risk posture?
Options
- APeriodic review of the risk register
- BKey risk indicators (KRIs)
- CDegree of senior management support
- DCompliance with industry regulations
How the community answered
(24 responses)- A8% (2)
- B88% (21)
- D4% (1)
Explanation
Key risk indicators (KRIs) enable an organization to continuously assess its information security risk posture by providing real-time, measurable data on emerging risks and vulnerabilities. KRIs help detect trends, monitor risk levels, and trigger proactive responses before incidents occur. While periodic risk register reviews, management support, and regulatory compliance are important, they do not provide continuous monitoring and assessment like KRIs do.
Topics
Community Discussion
No community discussion yet for this question.