Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 105 discussion

Actual exam question from Isaca's CISM
Question #: 105
Topic #: 1
[All CISM Questions]

Which of the following is MOST important when selecting an information security metric?

  • A. Ensuring the metric is repeatable
  • B. Aligning the metric to the IT strategy
  • C. Defining the metric in qualitative terms
  • D. Defining the metric in quantitative terms
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: B
Ensuring repeatability is important when selecting an information security metric, but it is not the most important factor. Repeatable metrics provide consistent and reliable data, which is crucial for tracking progress over time and making comparisons. However, repeatability alone is not enough to ensure that the metric is useful and meaningful. Aligning the metric to the IT strategy and ensuring that it supports the overall objectives of the organization is more critical, as this will ensure that the metric provides relevant and valuable information that can be used to drive meaningful improvements in information security.
upvoted 8 times
CISSPST
1 year, 1 month ago
I respectfully disagree. A security metric should align to business strategy, but not every security metric need align to IT strategy. For example, security resource management (metric: cost per user for security services) is integral to business strategy but is not impacted by and does not impact IT strategy. Answer is Repeatability.
upvoted 3 times
Perseus_68
1 year, 1 month ago
Looks like a semi trick question, IT strategy is too narrow of a focus as CISSPST mentions. Metrics can be used for many things. However, without repeatability the metric is worthless.
upvoted 2 times
...
...
...
angellorv
Highly Voted 6 months, 1 week ago
(A) ISACA CISM 15ed Review Manuan Section 1.6.1: Effective Security Metrics (SMART CRAAP): Specific, Measurable, Attainable, Relevant, Timely, Cost-effective, Repeatable, Accurate, Actionable, Predictive
upvoted 5 times
...
5fd6335
Most Recent 6 days, 16 hours ago
B is the best answer because When an information security metric is "aligned to the IT strategy," it means that the metric directly reflects and supports the overall goals and objectives of the organization's IT strategy, ensuring that security efforts are focused on protecting the most critical business assets and aligning with the broader IT roadmap.
upvoted 1 times
...
grandMa
3 weeks, 4 days ago
Selected Answer: B
this is confusing question.
upvoted 1 times
...
alifjouj
2 months, 2 weeks ago
Selected Answer: A
not every metric aligns with business
upvoted 2 times
...
helg420
6 months, 1 week ago
Selected Answer: A
While IT strategy encompasses the broader implementation of technology within an organization to meet its goals, the security strategy specifically focuses on protecting the organization's information and technology assets from threats and vulnerabilities. Ideally, information security metrics should align with the security strategy, which in turn should be developed in alignment with both the IT strategy and the overarching business objectives. Given the context of the available options and considering the importance of the security focus, the priority shifts to ensuring the metrics are not only aligned but also practical and actionable. Since "aligning to the security strategy" is not explicitly provided as an option, the focus should indeed revert to the fundamental qualities that make a metric useful for security purposes. Thus, Option A. Ensuring the metric is repeatable becomes significant
upvoted 2 times
...
c041644
7 months, 1 week ago
B, When selecting an information security metric, it's crucial to ensure it aligns with organizational goals aka IT strategy....
upvoted 1 times
...
e891cd1
8 months, 4 weeks ago
B Metrics should be SMART Specific Measurable Attainable Relevant and Timely.. aligning the metric with your strategy makes it more relevant is the logic i used.
upvoted 1 times
...
sphenixfire
1 year, 2 months ago
Selected Answer: B
I would say A but AIO 2nd means B A formal metrics program provides qualitative and quantitative data on the effective- ness of many elements of an organization’s security program and operations. Metrics can be developed via the SMART method: specific, measurable, attainable, relevant, and timely. Metrics must align with the organization’s mission, strategy, and objectives. Some metrics can be used to report on results in the recent past, but some metrics should serve as leading indicators or drive a call to action by the leadership team
upvoted 3 times
sphenixfire
1 year, 2 months ago
Strategic Alignment For a security program to be successful, it must align with the organization’s mission, strategy, goals, and objectives. A security program strategy and objectives should contain statements that can be translated into key measurements—the program’s key perfor- mance and risk metrics
upvoted 1 times
...
...
oluchecpoint
1 year, 2 months ago
B. Aligning the metric to the IT strategy When selecting an information security metric, it is most important to align the metric with the overall IT strategy and business objectives. This ensures that the metric is relevant and meaningful in the context of the organization's goals. Metrics should be tied to specific objectives and key performance indicators (KPIs) that support the strategic direction of the organization.
upvoted 1 times
...
drewl25
1 year, 3 months ago
Selected Answer: A
When selecting an information security metric, the most important consideration is to ensure that the metric is repeatable. A repeatable metric is one that can be consistently and reliably measured over time. It should be based on well-defined criteria, standardized measurement methods, and clear data collection processes. By having a repeatable metric, organizations can track and compare security performance consistently, identify trends, and measure progress towards security goals effectively.
upvoted 4 times
...
Az900500
1 year, 5 months ago
When Metric is measure quantitatively, it simply mean it is measurable and can be evaluated and will help proper investment into information security Selected Answer: D
upvoted 2 times
...
richck102
1 year, 5 months ago
D. Defining the metric in quantitative terms
upvoted 2 times
...
dark_3k03r
1 year, 6 months ago
Selected Answer: B
The most important thing about metrics is that they are tracking what matters to the business. With this in mind (B) is the correct answer. Rationale: A. It is great to have consistency, but it doesn't matter if it doesn't track anything meaningful. (C) and (D) are different ways of measuring things. One isn't better than the other, but again... they need to measure something meaningful which is (B).
upvoted 2 times
...
Abhey
1 year, 6 months ago
Selected Answer: D
When selecting an information security metric, it is MOST important to define the metric in quantitative terms (Option D). This means that the metric should be measurable and expressed in numerical values.
upvoted 3 times
...
bambs
1 year, 7 months ago
Selected Answer: D
Quantitative metrics use numerical data to measure and report on specific aspects of information security, such as the number of incidents, the time taken to resolve an issue, or the percentage of systems that are compliant with security policies
upvoted 4 times
dedfef
1 year, 7 months ago
you are wrong sir. Metrics dont have to be only quantitative
upvoted 1 times
...
...
MSKid
2 years ago
Selected Answer: A
CISM AIO 2nd - Security metrics are often used to observe technical IT security controls and processes and determine whether they are operating properly.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...