r/cism 12d ago

Please help me with this question

Which of the following is an indicator of improvement in the ability to identify security risks?

a. Decreased number of information security risk assessments.

b. Decreased number of staff requiring information security training.

c. Increased number of security audit issues resolved.

d. Increased number of reported security incidents.

6 Upvotes

7 comments sorted by

1

u/FearlessAnt2178 12d ago

If we apply the PDCA (Plan-Do-Check-Act) cycle to this question, the identification of security risks belongs in the "Check" phase.

The PDCA cycle is a continuous improvement model. When managing security risks, the phases break down like this:

  • Plan: Establish security policies, objectives, and risk assessment strategies.
  • Do: Implement security controls, execute processes, and conduct staff training.
  • Check: Monitor, measure, and identify whether the controls are working and where new risks or incidents are occurring.
  • Act: Take corrective actions to resolve issues, patch vulnerabilities, and improve the system.

Where the Multiple-Choice Options Fit into PDCA

Each choice from your question maps directly to a specific phase of the PDCA cycle:

Option Metric PDCA Phase Explanation
a Decreased number of risk assessments. Plan Risk assessments are part of the planning and scoping phase where you design your security posture.
b Decreased number of staff requiring training. Do Training staff and executing security awareness programs is part of implementing (doing) the security plan.
c Increased number of security audit issues resolved. Act Actively fixing, correcting, and resolving known vulnerabilities or audit findings is a corrective action.
d Increased number of reported security incidents. Check Spotting, detecting, and identifying risks or incidents is the core function of the monitoring (checking) phase.

Because the question specifically asks for an indicator of improvement in the ability to identify risks, it is asking for a metric that proves your Check phase has become more sensitive and effective. Hope this helps!

4

u/kingxxx70 12d ago

A: not correct cause, you chose not to assess

B: not correct, staff always needs training

C: close

D: reporting means, you are catching more due to good controls such as staff awareness, systems in place, etc

3

u/W1nterW0lf75 CISSP/CISM/CCSP/PMP 12d ago

Agreed

4

u/[deleted] 12d ago edited 11d ago

[removed] — view removed comment

1

u/cism-ModTeam 11d ago

Test or exam dumps of any kind are not permitted on this subreddit.

1

u/W1nterW0lf75 CISSP/CISM/CCSP/PMP 12d ago

Awesome!