Exam CISSP All QuestionsBrowse all questions from this exam
Question 339

Which of the following is established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls?

    Correct Answer: D

    Information Security Continuous Monitoring (ISCM) is designed to collect information according to pre-established metrics and utilizes information that is readily available, in part due to implemented security controls. It provides ongoing visibility into an organization's security posture by continuously assessing and analyzing security-related data.

Discussion

11 comments
stickerbush1970Option: D
Sep 22, 2022

Agree with D.

jackdryan
May 14, 2023

D is correct

krasskoOption: D
Sep 26, 2022

Agree with D

LoveguitarOption: D
Sep 19, 2022

D is the correct answer accorhttps://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program#:~:text=Definition(s)%3A,part%20through%20implemented%20security%20controls.ding to nist

SoleandheelOption: D
Dec 15, 2023

D. Information Security Continuous Monitoring (ISCM) Information Security Continuous Monitoring (ISCM) is a comprehensive process that involves the collection of security-related data and information to assess, analyze, and continuously monitor an organization's security posture. It uses pre-established metrics and leverages information available through implemented security controls to provide ongoing visibility into the effectiveness of an organization's security measures.

rdy4uOption: D
Oct 28, 2022

information security continuous monitoring (ISCM): "A program established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls." https://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program

Dee83Option: D
Jan 29, 2023

D. Information Security Continuous Monitoring (ISCM).

HanzoShimadaOption: D
Oct 22, 2022

It says it word for word on nist's official site. https://csrc.nist.gov/glossary/term/information_security_continuous_monitoring_program

8e1c45bOption: D
Jul 19, 2024

Vote for D

e58c193Option: C
Apr 4, 2024

The report which contains the results of performing a risk assessment or the formal output from the process of assessing risk." https://csrc.nist.gov/glossary/term/risk_assessment_repor

JAckThePipOption: C
Oct 5, 2022

Answer is C "The report which contains the results of performing a risk assessment or the formal output from the process of assessing risk." https://csrc.nist.gov/glossary/term/risk_assessment_report

ygcOption: C
Sep 25, 2022

C is correct, according to "available in part through implemented security controls"