Study. uk . com
  1. Home
  2. All questions
  3. Question 420

CISM study material · question 420 of 1000

An immature security programme attempts to report mission impact metrics and finds it cannot. Which explanation does NIST give?

  1. Impact metrics can only be reported annually, because a mission effect takes a full year to become visible in the reported figures
  2. Impact metrics require a specialist analysis tool that the programme has not yet been funded either to buy outright or to run with its own staff
  3. Impact metrics are reserved for organisations above a certain size, below which the mission effect cannot be separated out at all
  4. The type of metric a programme can produce depends on its maturity: an immature one can show only that policy exists
Show the answer

Answer: D. The type of metric a programme can produce depends on its maturity: an immature one can show only that policy exists

NIST states the specific aspect of security that metrics focus on depends on programme maturity, with evidence evolving from establishing the existence of policy through to identifying the impact of implementation on the mission.

Source: NIST SP 800-100 (NIST) — Sec. 7.3 Metrics Development Process

Challenge yourself on this topic → Study as cards