The most important measure of a security investment’s success is whether it delivers the anticipated risk reduction (D). CISM emphasizes that security investments are justified primarily by their ability to lower risk to within acceptable tolerance, not by compliance or financial return alone. Internal requirements (A) and standards compliance (B) are important but do not guarantee risk reduction. Financial benefits (C) are often indirect in security. Post-implementation reviews should validate whether the original risk assumptions were correct and whether residual risk aligns with management expectations.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit