When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:
consider the organizations business strategy.
consider the strategic objectives of the program.
leverage industry benchmarks.
identify the program's risk and compensating controls.
Submit