- Home
- All questions
- Question 387
CISM study material · question 387 of 1000
A team collects security measurement data already summarised by business unit. Which practice does NIST recommend instead, and why?
Show the answer
Answer: C. Collecting at the most discrete, unanalysed level available, so the same data can be aggregated in more than one way later
NIST states organisations should collect data to calculate measures at the most discrete, unanalysed level possible, which preserves the ability to aggregate it differently for different purposes.
Source: NIST SP 800-100 (NIST) — Table 2-1 Measurement and Metrics