Study. uk . com
  1. Home
  2. All questions
  3. Question 387

CISM study material · question 387 of 1000

A team collects security measurement data already summarised by business unit. Which practice does NIST recommend instead, and why?

  1. Collecting only the summary that each business unit supplies, so that storage cost and the effort of reconciliation are both kept down
  2. Collecting only the data that the owner of the source system has already validated, since an unvalidated figure cannot be defended at a review meeting
  3. Collecting at the most discrete, unanalysed level available, so the same data can be aggregated in more than one way later
  4. Collecting at whatever level the source system happens to provide it, since reworking the extract costs more than it will ever return
Show the answer

Answer: C. Collecting at the most discrete, unanalysed level available, so the same data can be aggregated in more than one way later

NIST states organisations should collect data to calculate measures at the most discrete, unanalysed level possible, which preserves the ability to aggregate it differently for different purposes.

Source: NIST SP 800-100 (NIST) — Table 2-1 Measurement and Metrics

Challenge yourself on this topic → Study as cards