正解:B
Security-related KRIs are metrics that measure the effectiveness of the information security profile in achieving the business objectives and managing the risks. Reviewing security-related KRIs can help to determine if the information security profile is aligned with business requirements, as they reflect the security performance and outcomes that are relevant for the business. Reviewing other options, such as KPIs, CSAs, or audits, may provide some insights into the security status, but they are not the best way to assess the alignment with business requirements, as they may not capture the business context and goals adequately.
References:
* https://www.nist.gov/cyberframework/examples-framework-profiles
* https://www.isaca.org/resources/isaca-journal/issues/2019/volume-5/accountability-for-information- security-roles-and-responsibilities-part-1
* https://www.isaca.org/resources/isaca-journal/issues/2017/volume-4/enterprise-security-architecturea- top-down-approach