CISSP · Question #164
Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations sta
The correct answer is A. Number of system compromises. When IT security staff is reduced and security is integrated into general IT operations, the most critical metric to monitor is the actual security outcome - specifically, whether systems are being compromised as a result of reduced oversight.
Question
Options
- ANumber of system compromises
- BNumber of audit findings
- CNumber of staff reductions
- DNumber of additional assets
How the community answered
(46 responses)- A59% (27)
- B24% (11)
- C4% (2)
- D13% (6)
Why each option
When IT security staff is reduced and security is integrated into general IT operations, the most critical metric to monitor is the actual security outcome - specifically, whether systems are being compromised as a result of reduced oversight.
Monitoring the number of system compromises directly measures the real-world security impact of reduced staffing, providing actionable evidence that resource allocation is insufficient to maintain adequate logical access controls. If compromises increase following staff reductions, this is the clearest indicator that security functions are being neglected and that resource reallocation or process changes are necessary. This outcome-based metric is the most important because it reflects the ultimate consequence of inadequate security administration.
Audit findings are a lagging, periodic indicator and may not surface quickly enough to inform real-time resource allocation decisions during active staff reductions.
The number of staff reductions is an input metric describing the cause of the problem, not an outcome metric that reflects whether security posture is being negatively affected.
The number of additional assets relates to scope expansion rather than measuring the effectiveness or adequacy of security operations under reduced staffing conditions.
Concept tested: Security resource allocation and outcome-based risk monitoring
Source: https://www.isaca.org/resources/isaca-journal/past-issues/2013/security-metrics-a-practical-framework-for-measuring-security-effectiveness
Topics
Community Discussion
No community discussion yet for this question.