The question is clear in asking how can we best measure the resiliency of the security program.
This is not all about DR. The best way to measure resiliency would be see how many incidents that actually end up causing a disruption. B is the right answer.
Successful disaster recovery tests confirm the response capabilities black on white.
In contrast a low number of incidents that have resulted in disasters does not confirm the response capabilities. You may assume that your DRP works - but you cannot confirm for sure. Therefore answer C is right.
Again, a tough question. I'm gonna go with C here since DR tests are there to test whether the system is resilient enough in the face of a disaster.
Just because a business didn't have many incidents that resulted in a disruption doesn't mean it's IT infrastructure is resilient. It can easily be luck of not facing an incident sever enough.
The metric that would best help determine the resiliency of IT infrastructure security controls is option C: Number of successful disaster recovery tests.
Disaster recovery tests are designed to simulate various potential incidents or disruptions to the IT infrastructure and evaluate the effectiveness of the security controls in place. By measuring the number of successful tests, organizations can assess how well their infrastructure can recover from such events and how resilient their security controls are. This metric provides a direct measurement of the ability to withstand and recover from potential security breaches or incidents.
C. Number of successful disaster recovery tests
This metric directly assesses the ability of IT infrastructure security controls to recover and maintain operations after a disaster or incident. Successful disaster recovery tests indicate that the controls are effective in ensuring resiliency and business continuity. Monitoring the number of successful tests over time can help identify trends and provide insights into the overall resiliency of the IT infrastructure security controls.
The number of successful disaster recovery tests provides a direct measure of the effectiveness and resiliency of IT infrastructure security controls. It demonstrates the ability of the organization to recover and restore critical systems and data in the event of a disruptive incident. By conducting regular tests and achieving successful outcomes, it indicates that the security controls in place are capable of withstanding and recovering from various disruptions or incidents.
Option C
C.
The number of successful disaster recovery tests is best suited to assess the resiliency of IT infrastructure security controls. Disaster recovery plans are critical to address system disruptions due to security events or natural disasters. Periodic testing can verify that the plan actually works. On the other hand, the percentage of unresolved high-risk audit issues is a less reliable metric because it is also affected if the issue is fixed before the audit is completed. Also, the frequency of system software updates, while it may help strengthen security controls, is not directly relevant to assessing resiliency.
B. Number of incidents resulting in disruptions is not the best measure of the robustness of the security controls in an IT infrastructure. This is because the frequency of security incidents is not an indicator of the robustness of security controls, which are affected by other factors as well.
I'm thinking this should be C. Number of successful disaster recovery tests. Perhaps I'm not
understanding the question.
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Dravidian
Highly Voted 1 year, 4 months agoJosef4CISM
Most Recent 1 month, 3 weeks agoAlexJacobson
7 months, 1 week ago03allen
2 months, 4 weeks agoPOWNED
8 months, 3 weeks agoPOWNED
8 months, 3 weeks agoAlizadeh
8 months, 3 weeks agoUncle_Lucifer
9 months agokoala_lay
9 months, 3 weeks agooluchecpoint
12 months agoAaronS1990
1 year agorichck102
1 year, 2 months agowello
1 year, 2 months agoSaisharan
1 year, 3 months agoTsubasa1234
1 year, 5 months agokoala_lay
9 months, 3 weeks agoCarlLimps
1 year, 6 months ago