QuestionQ119

Information Security Management

A capability assessment determines that an organization has comprehensive security policies and plans. It is highly effective at identifying security risks and managing them through effective controls. The effectiveness of information security controls is monitored and reported. The reports indicate that the controls are effective, so the team sees no reason to review or modify the policies or controls.

What capability level should this assessment report?

  • A Level 4
  • B Level 3
  • C Level 5
  • D Level 2
Explanation

Capability Level 4 represents a predictable process: control performance is monitored and measured, and the evidence shows the controls are effective. Level 5 requires ongoing improvement or innovation based on performance information; deciding not to review or change the policies or controls does not demonstrate that optimization activity.

Community Discussion

No comments yet. Be the first to start the discussion!