Study. uk . com
  1. Home
  2. All questions
  3. Question 435

CISM study material · question 435 of 1000

Which two existing data sources does NIST say security metrics can be derived from? Choose two.

  1. Corrective action plans and incident statistics
  2. Published vendor product roadmaps
  3. Employee satisfaction surveys run by the human resources team
  4. Security assessments and authorisation records
Show the answer

Answer: D. Security assessments and authorisation records
A. Corrective action plans and incident statistics

SP 800-100 draws metrics from records already kept — certification and accreditation, assessments, corrective action plans, incident statistics, and reviews whether internal or independent.

Source: NIST SP 800-100 (NIST) — Sec. 7.3 Metrics Development Process

Challenge yourself on this topic → Study as cards