CISM · Question #925
Which of the following should be of GREATEST concern to an information security manager when establishing a set of key risk indicators (KRIs)?
The correct answer is C. The impact of security risk on organizational objectives is not well understood. KRIs must reflect what matters most to the business and provide actionable insight. If the impact of security risk on organizational objectives is not understood, the organization cannot select meaningful KRIs or set appropriate thresholds, making this the greatest concern.
Question
Which of the following should be of GREATEST concern to an information security manager when establishing a set of key risk indicators (KRIs)?
Options
- AAnnual loss expectancy (ALE) has not yet been determined.
- BThe organization has no historical data on previous risk events.
- CThe impact of security risk on organizational objectives is not well understood.
- DSeveral business functions have been outsourced to third-party vendors.
How the community answered
(53 responses)- A21% (11)
- B4% (2)
- C62% (33)
- D13% (7)
Explanation
KRIs must reflect what matters most to the business and provide actionable insight. If the impact of security risk on organizational objectives is not understood, the organization cannot select meaningful KRIs or set appropriate thresholds, making this the greatest concern.
Topics
Community Discussion
No community discussion yet for this question.