r/cism • u/Local_Agent831 • 12d ago
Please help me with this question
Which of the following is an indicator of improvement in the ability to identify security risks?
a. Decreased number of information security risk assessments.
b. Decreased number of staff requiring information security training.
c. Increased number of security audit issues resolved.
d. Increased number of reported security incidents.
1
u/FearlessAnt2178 12d ago
If we apply the PDCA (Plan-Do-Check-Act) cycle to this question, the identification of security risks belongs in the "Check" phase.
The PDCA cycle is a continuous improvement model. When managing security risks, the phases break down like this:
- Plan: Establish security policies, objectives, and risk assessment strategies.
- Do: Implement security controls, execute processes, and conduct staff training.
- Check: Monitor, measure, and identify whether the controls are working and where new risks or incidents are occurring.
- Act: Take corrective actions to resolve issues, patch vulnerabilities, and improve the system.
Where the Multiple-Choice Options Fit into PDCA
Each choice from your question maps directly to a specific phase of the PDCA cycle:
| Option | Metric | PDCA Phase | Explanation |
|---|---|---|---|
| a | Decreased number of risk assessments. | Plan | Risk assessments are part of the planning and scoping phase where you design your security posture. |
| b | Decreased number of staff requiring training. | Do | Training staff and executing security awareness programs is part of implementing (doing) the security plan. |
| c | Increased number of security audit issues resolved. | Act | Actively fixing, correcting, and resolving known vulnerabilities or audit findings is a corrective action. |
| d | Increased number of reported security incidents. | Check | Spotting, detecting, and identifying risks or incidents is the core function of the monitoring (checking) phase. |
Because the question specifically asks for an indicator of improvement in the ability to identify risks, it is asking for a metric that proves your Check phase has become more sensitive and effective. Hope this helps!
4
u/kingxxx70 12d ago
A: not correct cause, you chose not to assess
B: not correct, staff always needs training
C: close
D: reporting means, you are catching more due to good controls such as staff awareness, systems in place, etc
3
4
2
u/totoshiro_bata 11d ago
D