Certified Information Security Manager CISM · Free Practice Question Easy
Question 73
What is the MOST effective way to evaluate the maturity level of an information security program among the options provided?
- A A. Review key performance indicators
- B B. Conduct a one-time audit
- C C. Rely on self-assessment only
- D D. Monitor incident reports
Reveal correct answer
Correct answer: A
Explanation
Correct Answer: A. Review key performance indicators Explanation: Regularly reviewing key performance indicators provides a continuous and systematic approach to assess the maturity level of an information security program. This ongoing evaluation allows for the identification of trends, areas for improvement, and the effectiveness of security measures over time. Conducting a one-time audit may provide a snapshot but lacks the continuous monitoring necessary for comprehensive maturity assessment. Relying solely on self-assessment may introduce bias and is not as reliable as objective performance indicators. Monitoring incident reports, while important, focuses more on reactive measures rather than the overall maturity of the program.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
