Which of the following MUST a security professional do in order to quantify the value of a security program to organization management?
Correct Answer: A
Reporting using metrics is the most important thing that a security professional must do in order to quantify the value of a security program to organization management. Metrics are measurable indicators that can be used to evaluate the performance, effectiveness, efficiency, and progress of a security program. Metrics can help the security professional to demonstrate the benefits, costs, risks, and return on investment of the security program, as well as to identify the gaps, weaknesses, and improvement opportunities. Metrics can also help the organization management to understand the security posture, align the security goals with the business objectives, and make informed decisions. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter
1: Security and Risk Management, page 23; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 1:
Security and Risk Management, page 85]