CISSP - Security Assessment and Testing (12% of the exam) - Section 6.3

Collect security process data including account management, management review, KPIs, backup verification, training, and DR/BC.

Collect and interpret security process data including KPIs, KRIs, account management records, backup verification results, training completion rates, and DR/BC test outcomes. Use this data to support management review and identify control gaps before they lead to incidents.

KPIsKRIsmanagement reviewbackup verificationaccount management data

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

A CISO is preparing the quarterly management review pack for the executive risk committee. The security operations team has produced a 40-page dashboard of raw metrics, including ticket volumes, scan findings, patch counts, and training completion rates. The committee has 30 minutes and has previously complained that prior packs were operational rather than strategic. What should the CISO do FIRST to make the pack fit for purpose?

  • AAdd benchmark comparisons against industry peers for every operational metric currently in the pack.
  • BReduce the pack to a single executive summary slide that lists the top five security incidents from the quarter.
  • CSchedule a longer review slot with the executive committee so the existing 40-page pack can be presented in full.
  • DConvert the raw operational metrics into a small set of KRIs and KPIs mapped to the organisation's risk appetite, with thresholds and trends. Correct
Recognise that management review data should be expressed as risk-tied KPIs and KRIs against thresholds, not as raw operational metrics. Security process data collected for management review must be transformed from operational measures into KPIs and KRIs that align with the organisation's risk appetite. Indicators with defined thresholds and trends let executives judge whether controls are operating within tolerance, decide on investment, and discharge their governance duty. Raw counts of tickets, scans, or patches do not on their own answer those questions.

Why A is wrong: Peer benchmarking is useful supporting context but does nothing to address the core problem that the pack is operational rather than tied to the organisation's risk appetite, so it is a secondary improvement at best.

Why B is wrong: An incident summary is reactive and narrow; management review requires forward-looking risk indicators, control effectiveness data, and trend analysis, not just a list of what went wrong last quarter.

Why C is wrong: Expanding the time slot accommodates the existing flawed format rather than fixing it; the issue is the level of abstraction of the data, not the volume of time, and executive attention is a scarce resource that should not be wasted on operational detail.

Why D is correct: Management review packs at executive level should present risk-tied indicators with thresholds and trend direction so the committee can make governance decisions; this converts operational data into the strategic signals they actually need.

See more CISSP practice questions, answers explained.

Exam traps in Security Assessment and Testing

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Immediately delete every account flagged as dormant or orphaned to remove the standing risk from the environment.

    Why it is wrong: Deletion before validation can destroy audit evidence, break dependent service accounts, and disrupt business processes; the correct response is suspension and structured review, not immediate destruction of identities.

  • It is a technical exercise where engineers verify that configured security controls match the documented baseline across in-scope production systems.

    Why it is wrong: Configuration baseline verification is a control testing activity carried out by operational or assessment staff, not a management review, which operates at a programme level and is owned by senior leadership.

  • Reviewing the nightly backup job logs each morning to confirm that every scheduled job completed with a success status and no warnings.

    Why it is wrong: Reviewing job completion logs is tempting because it is the most common operational check, but a successful write does not prove that the data is readable, complete, or restorable within the recovery time objective.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.