CISM · Question #65
Which of the following is the MOST appropriate metric to demonstrate the effectiveness of information security controls to senior management?
The correct answer is D. Annualized loss resulting from security incidents. The most effective metric to demonstrate information security control effectiveness to senior management is one that quantifies the financial impact of security incidents.
Question
Which of the following is the MOST appropriate metric to demonstrate the effectiveness of information security controls to senior management?
Options
- ANumber of security vulnerabilities uncovered with network scans
- BPercentage of servers patched
- CDowntime due to malware infections
- DAnnualized loss resulting from security incidents
How the community answered
(43 responses)- A16% (7)
- B5% (2)
- C9% (4)
- D70% (30)
Why each option
The most effective metric to demonstrate information security control effectiveness to senior management is one that quantifies the financial impact of security incidents.
The number of security vulnerabilities is a technical metric that does not directly translate into business impact or financial risk for senior management.
The percentage of servers patched is an operational metric indicating security hygiene, but it doesn't directly show the effectiveness of controls in reducing business loss to senior management.
Downtime due to malware infections is a valid operational metric, but annualized loss provides a more comprehensive financial quantification of security control effectiveness over time and in business terms.
Annualized loss resulting from security incidents is the most appropriate metric for senior management because it quantifies the financial impact of security failures in business terms, allowing them to understand the return on investment for security controls and the overall risk exposure. This metric directly addresses the business value and financial implications of security, which is paramount for executive decision-making.
Concept tested: Information security metrics for management
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.