Certified in Risk and Information Systems Control (CRISC) — Question 783

Which of the following is the BEST metric to demonstrate the effectiveness of an organization's software testing program?

Answer options

Correct answer: D

Explanation

The correct answer is D because the number of incidents resulting from software changes directly indicates the quality of the testing program; fewer incidents suggest effective testing. Options A, B, and C do not necessarily correlate with the effectiveness of the testing program, as they focus on coverage, time, and resources rather than actual outcomes.