An analyst prepares a unified security dashboard for a quarterly executive board meeting. Which included metric should be removed because it is inappropriately tiered for an executive audience?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
- ACompliance against required regulatory frameworks is a board-level governance metric.
- BThe share of critical business services meeting availability requirements is a business-outcome metric that executives can act on.
- CHigh-severity exposures on internet-facing assets summarize strategic risk in a way executives can understand.
- DCorrect: The IDS false-positive rate is an operational tuning metric for the SOC; it doesn't help a board make decisions, so it belongs in a technical report.