Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
A CISO is evaluating the effectiveness of the organization's information security program. The CISO wants to ensure that security controls remain effective against new and emerging threats without requiring constant manual review. Which of the following practices BEST supports this objective?
- ADeveloping a comprehensive security policy and procedure manual for all security personnel.
- BImplementing an annual third-party security audit and compliance review.
- CEstablishing a continuous monitoring program using automated tools and security analytics.
- DConducting monthly vulnerability scans of all network devices and servers.
Show answer & explanationAnswer & explanation
Correct answer: C. Establishing a continuous monitoring program using automated tools and security analytics.
To ensure security controls remain effective against new and emerging threats 'without requiring constant manual review', a continuous monitoring program is the most effective approach. Automated tools and security analytics provide real-time or near real-time visibility into the security posture, enabling proactive detection of deviations and emerging threats.
Why the other options are wrong
- A. Policies are foundational but do not actively assess the effectiveness of controls against new threats.
- B. Annual audits are periodic snapshots, not continuous, and involve manual review.
- D. Monthly vulnerability scans are periodic and focus on known vulnerabilities, not necessarily 'new and emerging threats' or continuous effectiveness.
Continuous Monitoring
The ongoing process of collecting, analyzing, and reporting security-related data and metrics to maintain awareness of an organization's security posture.
- Provides real-time security insights.
- Automated threat detection.
- Supports proactive risk management.
Memory trick: Keep an automated eye on everything, all the time.