Isaca Certified in Risk and Information Systems Control CRISC Question # 110 Topic 12 Discussion
CRISC Exam Topic 12 Question 110 Discussion:
Question #: 110
Topic #: 12
External auditors have found that management has not effectively monitored key security technologies that support regulatory objectives. Which type of indicator would BEST enable the organization to identify and correct this situation?
Key Control Indicators (KCIs) measure the performance and effectiveness of controls. When regulatory objectives are tied to technical controls (like firewalls or SIEM), KCIs can detect when those controls are failing or operating outside of thresholds. This allows proactive remediation before compliance violations occur.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit