正解:B
Key performance indicators (KPIs) are metrics that measure the effectiveness and ef-ficiency of information security processes and activities. They help senior manage-ment understand the status of information security compliance by providing relevant, timely and accurate information on the performance of security controls, the level of risk exposure, the return on security investment and the progress toward security ob-jectives. KPIs can also be used to benchmark the organization's security performance against industry standards or best practices. KPIs should be aligned with the organiza-tion's strategic goals and risk appetite, and should be reported regularly to senior man-agement and other stakeholders.
Reference:
* 1 Key Performance Indicators for Security Governance, Part 1 - ISACA
* 2 Key Performance Indicators for Security Governance, Part 2 - ISACA
* 3 Compliance Metrics and KPIs For Measuring Compliance Effectiveness - Reciprocity
* 4 14 Cybersecurity Metrics + KPIs You Must Track in 2023 - UpGuard