CISSP - Security Assessment and Testing - Section 6.3

Collect security process data including account management, management review, KPIs, backup verification, training, and DR/BC.

Collect and interpret security process data including KPIs, KRIs, account management records, backup verification results, training completion rates, and DR/BC test outcomes. Use this data to support management review and identify control gaps before they lead to incidents.

KPIsKRIsmanagement reviewbackup verificationaccount management data

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

A CISO is preparing the quarterly management review pack for the executive risk committee. The security operations team has produced a 40-page dashboard of raw metrics, including ticket volumes, scan findings, patch counts, and training completion rates. The committee has 30 minutes and has previously complained that prior packs were operational rather than strategic. What should the CISO do FIRST to make the pack fit for purpose?

  • AAdd benchmark comparisons against industry peers for every operational metric currently in the pack.
  • BReduce the pack to a single executive summary slide that lists the top five security incidents from the quarter.
  • CSchedule a longer review slot with the executive committee so the existing 40-page pack can be presented in full.
  • DConvert the raw operational metrics into a small set of KRIs and KPIs mapped to the organisation's risk appetite, with thresholds and trends. Correct
Recognise that management review data should be expressed as risk-tied KPIs and KRIs against thresholds, not as raw operational metrics. Security process data collected for management review must be transformed from operational measures into KPIs and KRIs that align with the organisation's risk appetite. Indicators with defined thresholds and trends let executives judge whether controls are operating within tolerance, decide on investment, and discharge their governance duty. Raw counts of tickets, scans, or patches do not on their own answer those questions.

Why A is wrong: Peer benchmarking is useful supporting context but does nothing to address the core problem that the pack is operational rather than tied to the organisation's risk appetite, so it is a secondary improvement at best.

Why B is wrong: An incident summary is reactive and narrow; management review requires forward-looking risk indicators, control effectiveness data, and trend analysis, not just a list of what went wrong last quarter.

Why C is wrong: Expanding the time slot accommodates the existing flawed format rather than fixing it; the issue is the level of abstraction of the data, not the volume of time, and executive attention is a scarce resource that should not be wasted on operational detail.

Why D is correct: Management review packs at executive level should present risk-tied indicators with thresholds and trend direction so the committee can make governance decisions; this converts operational data into the strategic signals they actually need.

See more CISSP practice questions with worked answers.

More in this domain

Back to all Security Assessment and Testing objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.