CRISC · Question #467
A risk practitioner is defining metrics for security threats that were not identified by antivirus software. Which type of metric is being developed?
The correct answer is B. Key risk indicator (KRI). Metrics for security threats not identified by existing controls, like antivirus, are Key Risk Indicators (KRIs), as they signal potential future risks or exposures.
Question
A risk practitioner is defining metrics for security threats that were not identified by antivirus software. Which type of metric is being developed?
Options
- AKey control indicator (KCI)
- BKey risk indicator (KRI)
- COperational level agreement (OLA)
- DService level agreement (SLA)
How the community answered
(28 responses)- A4% (1)
- B71% (20)
- C7% (2)
- D18% (5)
Why each option
Metrics for security threats not identified by existing controls, like antivirus, are Key Risk Indicators (KRIs), as they signal potential future risks or exposures.
Key Control Indicators (KCIs) measure the effectiveness of controls, not the emergence of new or undetected threats.
Key Risk Indicators (KRIs) are metrics used to monitor the level of risk an organization faces, providing an early warning signal of increasing risk exposure. When antivirus software fails to identify threats, it indicates a potential gap or emerging threat landscape, which is precisely what a KRI would track to alert management to heightened risk.
Operational Level Agreements (OLAs) are internal agreements that define service levels between internal departments, unrelated to external threat detection.
Service Level Agreements (SLAs) are external agreements defining the expected level of service from a provider, which is not directly relevant to identifying new threats.
Concept tested: Key Risk Indicator (KRI) definition
Topics
Community Discussion
No community discussion yet for this question.