組織のポリシーでは、重要なセキュリティ パッチはパッチが利用可能になってから 3 週間以内に本番環境に展開することが求められています。ポリシーの遵守を確認するための最適な指標は次のどれですか。
正解:A
The best metric to verify adherence to the policy that requires critical security patches to be deployed in production within three weeks of patch availability is the maximum time gap between patch availability and deployment, as it measures the longest duration that the organization takes to apply the patches, and ensures that it does not exceed the policy limit. The other options are not the best metrics, as they may not reflect the actual or optimal compliance with the policy, or may not be relevant or measurable for the policy, respectively. References = CRISC Review Manual, 7th Edition, page 110.