exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 255 discussion

Actual exam question from Isaca's CISM
Question #: 255
Topic #: 1
[All CISM Questions]

Which of the following would MOST effectively communicate the benefits of an information security program to executive management?

  • A. Key performance indicators (KPIs)
  • B. Threat models
  • C. Key risk indicators (KRIs)
  • D. Industry benchmarks
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 3 months ago
Selected Answer: C
The Correct answer is (C.) Key risk indicators (KRIs), cause the main purpose of a security program is to reduce risk. So it should be measured on its ability to reduce said risk and that is what KRI is designed to do. Rationale: (A.) Key performance indicators (KPIs) is incorrect cause it measure performances efficiencies, not risk reduction. (B.) Threat models is incorrect cause it is not a form risk measurement. (D.) Industry benchmarks is not the correct answer cause it is not organization specific.
upvoted 6 times
...
Noragretz
Most Recent 1 month, 1 week ago
Selected Answer: C
Question is hard to determine if you are selling a program to implement, or touting the successes/benefits of the program that has been implemented. It depends with way you interpret this question. I chose C because if I wanted to implement a program I’d explain what our current key risks are and use a heat map.
upvoted 1 times
...
bronay
4 months, 2 weeks ago
Selected Answer: C
Its not asking about measurement or trend effectiveness.
upvoted 2 times
...
oluchecpoint
6 months, 4 weeks ago
Selected Answer: A
A. Key performance indicators (KPIs) Key performance indicators (KPIs) are typically the most effective way to communicate the benefits of an information security program to executive management. KPIs provide measurable metrics and data that can demonstrate the impact and effectiveness of the security program in a way that is easily understandable by executives.
upvoted 3 times
...
blehbleh
7 months, 3 weeks ago
Selected Answer: A
Its A. Benefits are shown by performance metrics.
upvoted 1 times
...
Uncle_Lucifer
9 months ago
Selected Answer: A
WTH does KRI have to do with communicating benefits? Risk is a potential that can mature into an issue. If its not an issue, reporting it does not show any benefit, since a risk is just a potential issue. KPI is showing performance. That's the correct answer
upvoted 2 times
...
POWNED
9 months, 1 week ago
Selected Answer: A
I guess you guys need me to define KRI: Key risk indicators are metrics that predict potential risks that can negatively impact businesses. They provide a way to quantify and monitor each risk. Think of them as change-related metrics that act as an early warning risk detection system to help companies effectively monitor, manage and mitigate risks. KRI in no way is going to communicate the benefits of the security program to executive management. The Answer is KPI and is also the correct answer in similar questions before this one.
upvoted 4 times
...
XJ
10 months ago
C - https://blog.einnosec.com/index.php/2020/07/07/information-security-kri-kpi-relevant-to-ciso-cio-and-board-part-i/#:~:text=The%20KRIs%20are%20like%20an%20early%20warning%20system,impact%20it%20would%20have%20on%20the%20organization%E2%80%99s%20KPI.
upvoted 1 times
...
oluchecpoint
12 months ago
A. Key performance indicators (KPIs) Key performance indicators (KPIs) are typically the most effective way to communicate the benefits of an information security program to executive management. KPIs provide measurable metrics and data that can demonstrate the impact and effectiveness of the security program in a way that is easily understandable by executives.
upvoted 2 times
...
Hugo1717
1 year ago
Selected Answer: A
The correct answer is A. Key performance indicators (KPIs). Explanation: Among the options provided, Key Performance Indicators (KPIs) would most effectively communicate the benefits of an information security program to executive management. KPIs are measurable values that demonstrate the effectiveness and impact of an initiative or program.
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: A
The CISM Review Manual, 15th Edition, from ISACA (Page 58) states: "KPIs are used to measure the achievement of strategic objectives... These metrics should be capable of measuring the extent to which the objectives are being achieved and, hence, can indicate where improvement efforts should be focused."
upvoted 4 times
...
Goseu
1 year, 1 month ago
Selected Answer: C
I like C here
upvoted 1 times
...
Jae_kes
1 year, 2 months ago
Selected Answer: A
A. Key performance indicators (KPIs)
upvoted 1 times
...
jjj378
1 year, 2 months ago
Selected Answer: A
A. Key performance indicators (KPIs)
upvoted 1 times
...
richck102
1 year, 2 months ago
C. Key risk indicators (KRIs)
upvoted 2 times
...
DASH_v
1 year, 3 months ago
Selected Answer: C
The question is asking “benefits of a security program". The only benefit is risk being appropriately managed and within the risk tolerance, in which measured/reflected by KRI.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago