nerdexam
Isaca

CISA · Question #104

The MOST important measure of the effectiveness of an organization's security program is the:

The correct answer is B. adverse impact of incidents on critical business activities.. The most crucial measure of a security program's effectiveness is the adverse impact that security incidents have on an organization's critical business activities, as it directly reflects the program's ability to protect business operations.

Submitted by brentm· Apr 18, 2026Governance and Management of IT

Question

The MOST important measure of the effectiveness of an organization's security program is the:

Options

  • Acomparison with critical incidents experienced by competitors.
  • Badverse impact of incidents on critical business activities.
  • Cnumber of vulnerability alerts escalated to senior management.
  • Dnumber of new vulnerabilities reported.

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    70% (31)
  • C
    5% (2)
  • D
    9% (4)

Why each option

The most crucial measure of a security program's effectiveness is the adverse impact that security incidents have on an organization's critical business activities, as it directly reflects the program's ability to protect business operations.

Acomparison with critical incidents experienced by competitors.

Comparing incidents with competitors provides benchmarking data but doesn't directly measure the effectiveness of the *organization's own* security program in protecting its specific assets.

Badverse impact of incidents on critical business activities.Correct

A security program's primary objective is to protect an organization's assets and operations from security threats, minimizing disruption and financial loss. Therefore, measuring the actual adverse impact of incidents on critical business activities directly assesses how well the program is achieving its core mission and protecting business value.

Cnumber of vulnerability alerts escalated to senior management.

The number of vulnerability alerts escalated measures reporting processes or vulnerability discovery, not the overall effectiveness of preventing or mitigating business impact.

Dnumber of new vulnerabilities reported.

The number of new vulnerabilities reported indicates discovery efforts or new risks, but not the overall effectiveness of the security program in defending against those vulnerabilities or their business impact.

Concept tested: Security program effectiveness measurement

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/manage/considerations/security#measure-effectiveness

Topics

#Security Program Effectiveness#Security Metrics#Business Impact Analysis#Incident Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice