The correct answer is C because security metrics provide measurable evidence of whether controls are operating effectively and achieving intended outcomes. Establishing and reporting metrics allows the information security manager to monitor trends, identify control weaknesses, support management decisions, and demonstrate program performance. Benchmarking can provide useful external comparison, but it does not directly measure the organization’s own control effectiveness. Reviewing audit logs is valuable for specific detective controls, but it is too narrow to monitor the overall effectiveness of security controls. Threat assessments help identify changing threat conditions, but they do not directly show whether controls are performing as intended. CISM emphasizes performance measurement, monitoring, and reporting as essential components of managing an information security program. Metrics should be aligned with security objectives, risk appetite, and business goals. Effective metrics allow management to determine whether controls remain appropriate, efficient, and effective in reducing risk to acceptable levels.
[Reference: CISM Information Security Program Development and Management; security metrics, control monitoring, and performance reporting principles., , ]
Submit