CISSP · Question #891
Which of the following is the BEST reason for the use of security metrics?
The correct answer is D. They quantify the effectiveness of security processes. Security metrics are measurement tools used to quantify and evaluate the performance and effectiveness of security controls and processes, enabling data-driven decision-making.
Question
Options
- AThey ensure that the organization meets its security objectives.
- BThey provide an appropriate framework for Information Technology (IT) governance.
- CThey speed up the process of quantitative risk assessment.
- DThey quantify the effectiveness of security processes.
How the community answered
(37 responses)- A5% (2)
- B8% (3)
- C3% (1)
- D84% (31)
Why each option
Security metrics are measurement tools used to quantify and evaluate the performance and effectiveness of security controls and processes, enabling data-driven decision-making.
Security metrics measure and report on security performance, but they do not inherently ensure that objectives are met - that is the role of security controls, governance processes, and management oversight.
IT governance frameworks (such as COBIT or ISO 38500) provide structural guidance for aligning IT with business goals; security metrics are an input to governance but do not constitute a governance framework themselves.
Quantitative risk assessment relies on probability and impact data, threat modeling, and asset valuation methodologies; while metrics can inform risk assessments, accelerating the risk assessment process is not the primary purpose of security metrics.
The primary purpose of security metrics is to quantify the effectiveness of security processes by converting qualitative security activities into measurable, objective data points. This allows organizations to track performance over time, identify weaknesses, and demonstrate the value of security investments with concrete evidence rather than subjective assessments.
Concept tested: Purpose and function of security metrics
Source: https://csrc.nist.gov/publications/detail/sp/800-55/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.