- Home
- All questions
- Question 426
CISM study material · question 426 of 1000
A metric shows that only a third of security plans are approved, but nobody can say why. Which remedy does NIST describe?
Show the answer
Answer: B. Collecting the reasons as a separate metric or as implementation evidence, since one metric rarely explains poor performance
NIST gives exactly this example: determining that the percentage of approved security plans is low is not helpful for correcting it, so information on the reasons must be collected as separate metrics or as implementation evidence.
Source: NIST SP 800-100 (NIST) — Sec. 7.4.2 Collect Data and Analyze Results