CISM Certified Information Security Manager – Question1135

Which of the following is the BEST indicator that an effective security control is built into an organization?

A.
The monthly service level statistics indicate a minimal impact from security issues.
B. The cost of implementing a security control is less than the value of the assets.
C. The percentage of systems that is compliant with security standards.
D. The audit reports do not reflect any significant findings on security.

Correct Answer: A

Explanation:

Explanation: The best indicator of effective security control is the evidence of little disruption to business operations. Choices B, C and D can support this evidence, but are supplemental to choice A.