CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard
A Chief Compliance Officer (CCO) is implementing a new compliance monitoring program. They want to ensure that the program not only identifies non-compliance but also provides insights into the root causes and trends of compliance failures across the organization. Which type of compliance metric would be most effective for achieving this goal?
- AOutcome-based metrics
- BInput-based metrics
- CActivity-based metrics
- DOutput-based metrics
Show answer & explanationAnswer & explanation
Correct answer: A. Outcome-based metrics
Outcome-based metrics focus on the results and impact of compliance efforts, directly providing insights into root causes and trends of failures, rather than just measuring activities or immediate outputs. This allows for more strategic improvement.
Why the other options are wrong
- B. Input-based metrics measure resources dedicated to compliance (e.g., budget, staff), not the effectiveness or root causes of failures.
- C. Activity-based metrics track tasks performed (e.g., number of audits), similar to output metrics, without delving into underlying causes of non-compliance.
- D. Output-based metrics measure direct results of compliance activities (e.g., number of policies reviewed), but don't explain why failures occur.
Outcome-based Compliance Metrics
Metrics that measure the ultimate impact and effectiveness of compliance efforts, focusing on observable changes in risk posture, reduction in incidents, or improvements in overall compliance culture.
- Focus on 'why' and 'what changed'.
- Provide insights into root causes and trends.
- More strategic for continuous improvement.
Memory trick: Outcomes show you the 'why', not just the 'what'.