Certified in Risk and Information Systems Control (CRISC) — Question 1413
External auditors have found that management has not effectively monitored key security technologies that support regulatory objectives. Which type of indicator would BEST enable the organization to identify and correct this situation?
Answer options
- A. Key management indicator (KMI)
- B. Key control indicator (KCI)
- C. Key performance indicator (KPI)
- D. Key risk indicator (KRI)
Correct answer: B
Explanation
The correct answer is B, Key control indicator (KCI), as it focuses on the effectiveness of controls that ensure compliance with regulations. The other options, such as KMI, KPI, and KRI, may track various aspects of management, performance, or risk but do not specifically address the monitoring of controls necessary for regulatory compliance.