nerdexam
(ISC)2

CISSP · Question #155

Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lac

The correct answer is A. audit findings.. The primary way to measure the effectiveness of the security program is through the audit findings. The audit findings are the results or the outcomes of the audit process, which is a systematic and independent examination of the security activities and initiatives, to determine

Submitted by yousef_jo· Mar 5, 2026Security Assessment and Testing

Question

Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lacking the other necessary components to have an effective security program. There are numerous initiatives requiring security involvement. The effectiveness of the security program can PRIMARILY be measured through

Options

  • Aaudit findings.
  • Brisk elimination.
  • Caudit requirements.
  • Dcustomer satisfaction.

How the community answered

(60 responses)
  • A
    62% (37)
  • B
    5% (3)
  • C
    10% (6)
  • D
    23% (14)

Explanation

The primary way to measure the effectiveness of the security program is through the audit findings. The audit findings are the results or the outcomes of the audit process, which is a systematic and independent examination of the security activities and initiatives, to determine whether they comply with the security policies and standards, and whether they achieve the security objectives and goals. The audit findings can help to evaluate the effectiveness of the security program, as they can identify and report the strengths and the weaknesses, the successes and the failures, and the gaps and the risks of the security program, and they can provide the recommendations and the feedback for the improvement and the enhancement of the security program. Risk elimination, audit requirements, and customer satisfaction are not the primary ways to measure the effectiveness of the security program, as they are related to the impossibility, the necessity, or the quality of the security program, not the evaluation or the assessment of the security program.

Topics

#security program effectiveness#security metrics#audit findings#security assessment

Community Discussion

No community discussion yet for this question.

Full CISSP Practice