Study. uk . com
  1. Home
  2. All questions
  3. Question 698

CISM study material · question 698 of 1000

NIST states that security cannot be measured perfectly. Which reason does it give, and what does it advise instead?

  1. The gap between mathematical models and practical implementations; experiment with relative metrics and approaches over time
  2. The subjectivity of the assessors making each judgement; use only the automated measures that are gathered directly from the deployed tooling
  3. The cost of collection; measure only high-impact systems
  4. The absence of any recognised standard for the discipline; adopt an international framework and measure the whole programme against it
Show the answer

Answer: A. The gap between mathematical models and practical implementations; experiment with relative metrics and approaches over time

SP 800-55v1 traces the difficulty to the distance between mathematical models and how things are actually built, and recommends trying relative metrics, models and approaches over time to find what indicates well.

Source: NIST SP 800-55 Vol. 1 (NIST) — Ch. 3 Measurement Considerations

Challenge yourself on this topic → Study as cards