nerdexam
Isaca

CISM · Question #101

The PRIMARY reason for senior management to monitor information security metrics is to ensure:

The correct answer is B. alignment of information security with corporate governance.. Senior management monitors information security metrics primarily to ensure that security efforts are aligned with and support the organization's overall corporate governance objectives.

Submitted by anjalisingh· Apr 18, 2026Information Security Governance

Question

The PRIMARY reason for senior management to monitor information security metrics is to ensure:

Options

  • Aalignment of the information security budget to corporate funding.
  • Balignment of information security with corporate governance.
  • Calignment of security and IT objectives.
  • Dalignment with risk mitigation efforts.

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    94% (44)
  • C
    4% (2)

Why each option

Senior management monitors information security metrics primarily to ensure that security efforts are aligned with and support the organization's overall corporate governance objectives.

Aalignment of the information security budget to corporate funding.

Aligning the security budget to corporate funding is a financial management task, a subset of broader corporate governance, not the primary reason for monitoring security performance.

Balignment of information security with corporate governance.Correct

Senior management's primary reason for monitoring information security metrics is to ensure alignment of information security with corporate governance, demonstrating due diligence and accountability in managing enterprise risks. Metrics provide a quantifiable way for management to assess if security investments and initiatives are effectively supporting strategic business goals and regulatory compliance.

Calignment of security and IT objectives.

Alignment of security and IT objectives is important, but corporate governance encompasses a broader organizational view beyond just IT operations.

Dalignment with risk mitigation efforts.

Alignment with risk mitigation efforts is a core function of security, but the *reason* senior management monitors it is to ensure these efforts are compliant and contribute to overall governance and strategic objectives.

Concept tested: Information security governance and metrics

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001

Topics

#Information security governance#Metrics#Senior management oversight#Strategic alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice