Study. uk . com
  1. Home
  2. All questions
  3. Question 414

CISM study material · question 414 of 1000

An organisation with no documented procedures struggles to produce meaningful security metrics. Which explanation does NIST give?

  1. With no policy or procedure in place there is no defined standard to measure against, so metrics are hard to come by
  2. Metrics require an automated collection tool that the organisation lacks
  3. Metrics require an external assessor to be valid
  4. Metrics can only be produced for technical controls
Show the answer

Answer: A. With no policy or procedure in place there is no defined standard to measure against, so metrics are hard to come by

SP 800-100 makes workable policies and procedures, carrying the authority to enforce them, the second component of a metrics programme — precisely because measurement needs something to measure against.

Source: NIST SP 800-100 (NIST) — Ch. 7 Performance Measures

Challenge yourself on this topic → Study as cards