正解:A
Comprehensive and Detailed Step-by-Step Explanation:
Thespeed at which security threats are mitigatedis akey indicatorof an organization'srisk management effectiveness.
* Option A (Correct):Response time to security threatsmeasures how efficiently security teams detect, analyze, and mitigate risks, providingclear insight into security operations.
* Option B (Incorrect):The number of security controls auditeddoes not indicatehow well risk is being managed, only that reviews are taking place.
* Option C (Incorrect):Log analysis speedis useful, but it does notdirectly measure risk mitigation effectiveness.
* Option D (Incorrect):Risk register entriesindicate known risks but do not provide insight intohow well those risks are managed.
Reference:ISACA CISA Review Manual -Domain 5: Protection of Information Assets- Coverssecurity metrics, KPIs, and risk management evaluation.