Study. uk . com
  1. Home
  2. All questions
  3. Question 426

CISM study material · question 426 of 1000

A metric shows that only a third of security plans are approved, but nobody can say why. Which remedy does NIST describe?

  1. Removing the metric because it is not actionable
  2. Collecting the reasons as a separate metric or as implementation evidence, since one metric rarely explains poor performance
  3. Lowering the target until the current rate becomes acceptable, so that the metric stops reporting a shortfall in each reporting period
  4. Escalating the finding directly to the authorising official, who can then compel the outstanding security plans to be approved at once
Show the answer

Answer: B. Collecting the reasons as a separate metric or as implementation evidence, since one metric rarely explains poor performance

NIST gives exactly this example: determining that the percentage of approved security plans is low is not helpful for correcting it, so information on the reasons must be collected as separate metrics or as implementation evidence.

Source: NIST SP 800-100 (NIST) — Sec. 7.4.2 Collect Data and Analyze Results

Challenge yourself on this topic → Study as cards