Certified in Risk and Information Systems Control (CRISC) — Question 707

Which of the following key risk indicators (KRIs) is MOST effective for monitoring risk related to a bring your own device (BYOD) program?

Answer options

Correct answer: A

Explanation

The correct answer, A, is the most effective KRI because it directly reflects the risk exposure from BYOD devices through incident frequency. The other options, while relevant, do not provide immediate insights into actual risk occurrences: B focuses on budget rather than incidents, C measures enrollment without reflecting risk, and D indicates policy acceptance without showing actual risk impact.