Which of the following is the BEST indication of an effective information security program?
Comprehensive and Detailed Step-by-Step Explanation:
An effective information security program aims to manage risks to acceptable levels while supporting business objectives.
A . Risk is treated to an acceptable level: This is the BEST answer as it directly reflects the program's success in mitigating risks within the organization's tolerance levels.
B . The number of security incidents reported by staff has increased: An increase in reported incidents might indicate improved awareness but does not necessarily reflect overall effectiveness.
C . Key risk indicators (KRIs) are established: KRIs are important for monitoring risks but do not indicate whether risks are being effectively managed.
D . Policies are reviewed and approved by senior management: While essential, this action alone does not demonstrate the program's effectiveness.
Sherita
4 months agoJina
4 months agoAvery
4 months agoDorian
3 months agoAlesia
3 months agoWenona
3 months agoJeannetta
4 months agoKiley
4 months agoEdelmira
4 months agoJulene
4 months agoCassi
5 months agoShayne
5 months agoFannie
4 months agoBarrett
4 months agoRodolfo
5 months agoRaina
5 months ago