The organizations level of security risk acceptance should be considered when selecting recommended
safeguards. correct answers True
Which of the following orders is consistent with the KPI, KPX, and KRI formation? correct answers
metrics, KPI, KPx, KRI, Dashboard
Which phase of the information security measurement system lifecycle involves gaining a solid
appreciation of the organization information security-related information needs? correct answers Phase 1
Risk monitoring provides organization with the means to verify compliance, determine the effectiveness
of risk measures, and identify risk-impacting changes to organizational information systems and
environments of operations. correct answers True
KPIs do not necessarily need to be tied to organizational strategy. correct answers True
In addition to deciding on appropriate monitoring activities across the risk management tiers,
organizations also decide how monitoring is to be conducted (e.g., automated or manual approaches) and
the frequency of monitoring activities. correct answers True
A KPx is a summary of one or more KRIs. correct answers False
PRAGMATIC is a correct answers Security Measurement System
Key Risk Indicators should be tied to one or more Key Performance Indexes. correct answers True
Which of the following is NOT a phase in the information security measurement system lifecycle? correct
answers Remove the measurement system
Change management ensures that similar systems have the same, or at least similar, configurations.
correct answers False