Which of the following is the MOST important characteristic of an effective information security metric?
The metric expresses residual risk relative to risk tolerance.
The metric is frequently reported to senior management.
The metric directly maps to an industry risk management framework.
The metric compares the organization ' s inherent risk against its risk appetite.
Submit