CISA Certified Information Systems Auditor – Question2084

Which of the following would be the BEST way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS)?

A.
Perform industry research annually and document the overall ranking of the IPS.
B. Perform a penetration test to demonstrate the ability to protect.
C. Establish and present appropriate metrics that track performance.
D. Provide yearly competitive pricing to illustrate the value of the IPS.

Correct Answer: C