nerdexam
(ISC)2

CISSP · Question #164

Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations sta

The correct answer is A. Number of system compromises. When IT security staff is reduced and security is integrated into general IT operations, the most critical metric to monitor is the actual security outcome - specifically, whether systems are being compromised as a result of reduced oversight.

Submitted by lars.no· Mar 5, 2026Security and Risk Management

Question

Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles. When determining appropriate resource allocation, which of the following is MOST important to monitor?

Options

  • ANumber of system compromises
  • BNumber of audit findings
  • CNumber of staff reductions
  • DNumber of additional assets

How the community answered

(46 responses)
  • A
    59% (27)
  • B
    24% (11)
  • C
    4% (2)
  • D
    13% (6)

Why each option

When IT security staff is reduced and security is integrated into general IT operations, the most critical metric to monitor is the actual security outcome - specifically, whether systems are being compromised as a result of reduced oversight.

ANumber of system compromisesCorrect

Monitoring the number of system compromises directly measures the real-world security impact of reduced staffing, providing actionable evidence that resource allocation is insufficient to maintain adequate logical access controls. If compromises increase following staff reductions, this is the clearest indicator that security functions are being neglected and that resource reallocation or process changes are necessary. This outcome-based metric is the most important because it reflects the ultimate consequence of inadequate security administration.

BNumber of audit findings

Audit findings are a lagging, periodic indicator and may not surface quickly enough to inform real-time resource allocation decisions during active staff reductions.

CNumber of staff reductions

The number of staff reductions is an input metric describing the cause of the problem, not an outcome metric that reflects whether security posture is being negatively affected.

DNumber of additional assets

The number of additional assets relates to scope expansion rather than measuring the effectiveness or adequacy of security operations under reduced staffing conditions.

Concept tested: Security resource allocation and outcome-based risk monitoring

Source: https://www.isaca.org/resources/isaca-journal/past-issues/2013/security-metrics-a-practical-framework-for-measuring-security-effectiveness

Topics

#security metrics#risk indicators#incident rates#security monitoring

Community Discussion

No community discussion yet for this question.

Full CISSP Practice