Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 797 discussion

Actual exam question from Isaca's CISM
Question #: 797
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to include in monthly information security reports to the board?

  • A. Root cause analysis of security incidents
  • B. Threat intelligence
  • C. Risk assessment results
  • D. Trend analysis of security metrics
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CarlLimps
Highly Voted 1 year, 8 months ago
Selected Answer: D
D. If you are reporting to the board or senior leadership, IMO, you would want to keep it high level by using metrics to communicate with your analysis.
upvoted 5 times
cosmo4ng
1 year, 7 months ago
Agreed
upvoted 1 times
...
...
Booict
Most Recent 3 months ago
Selected Answer: D
D - Provides the board with a comprehensive view of the organization’s security posture over time, helping them make informed decisions about security investments and strategies.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: C
Providing the results of risk assessments can be considered the most crucial aspect of information security reporting to the board. This allows the board to understand the current state of security in the organization, including identified risks and their potential impact. It also helps prioritize resources and make informed decisions regarding security investments.
upvoted 1 times
pgonza
2 months, 3 weeks ago
You cant conduct a risk assessment every month. So trends and security metrics are more ideal
upvoted 1 times
...
...
richck102
1 year, 4 months ago
D. Trend analysis of security metrics
upvoted 1 times
...
Gr3yGh0sT
1 year, 6 months ago
Selected Answer: D
Clearly D.
upvoted 2 times
...
N1co_o
1 year, 8 months ago
Going for D. You dont do monthly risk assessment ?
upvoted 4 times
AlexJacobson
9 months, 3 weeks ago
Touche!
upvoted 1 times
...
...
Souvik124
1 year, 9 months ago
All of the options listed are important to include in monthly information security reports to the board, but if we have to choose the one that is MOST important, it would be option C, "Risk assessment results."
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...