Certified Information Security Manager (CISM)Information Security Risk ManagementEasy

An organization is evaluating its information security program's maturity and effectiveness. The CISO wants to ensure that security controls are not only implemented but also continuously monitored and regularly reviewed to adapt to evolving threats and business changes. Which concept BEST describes this ongoing process of verification and adaptation?

  1. AContinuous monitoring.
  2. BIncident response planning.
  3. COne-time security audit.
  4. DSecurity baseline configuration.
Show answer & explanation

Correct answer: A. Continuous monitoring.

Continuous monitoring is the ongoing surveillance, assessment, and review of an organization's security posture. It ensures that security controls remain effective, risks are continuously assessed, and the security program adapts to changes in the environment and threat landscape.

Why the other options are wrong

  • B. Incident response planning deals with reacting to breaches, not the continuous verification and adaptation of the overall security posture.
  • C. A one-time audit provides a snapshot but lacks the ongoing, adaptive nature described.
  • D. Baseline configurations are a starting point, not an ongoing process of adaptation.

Continuous Monitoring

The ongoing process of collecting, analyzing, and reporting data from security controls and systems to maintain a continuous awareness of an organization's security posture.

  • Ensures security controls remain effective.
  • Facilitates adaptation to evolving threats.
  • Supports real-time risk assessment.

Memory trick: Continuous Monitoring: Always Watching, Always Adapting.

More Information Security Risk Management questions