What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?
A. Agreeing on baseline values for the metrics
B. Developing a dashboard for communicating the metrics
C. Providing real-time insight on the security posture of the
organization
D. Benchmarking the expected value of the metrics against industry
standards
Correct Answer: A???? or B?????? or C????????
______________________
Note
■ Some good websites claim that the correct answer is A ("Agreeing on baseline values for the metrics").
■ Others good websites claim that the correct answer is C ("Providing real-time insight on the security posture of the organization").
■ From my point of view I like option C ("Providing real-time insight on the security posture of the organization")., at the same time option B ("Developing a dashboard for communicating the metrics") is for me more realistic.
■ I would like to know your opinion…..
Many thanks!
The correct option for this question is the option A.) Agreeing on baseline values for the metrics because as we are representing the information of the security to a standard commitee so we need a security metrics that are in accordance with a certains standards which means we should be agreeing on baseline values of the metrics and all the metrics , which can be for performance or security , we have a certain agreement on the baseline values to determine the security increase or security level of the system and we this baseline values to compare the security metrics of our product to a baseline values.
Get Answers For Free
Most questions answered within 1 hours.