nerdexam
Isaca

CISM · Question #12

Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?

The correct answer is C. Information security program metrics. To effectively communicate the status of an information security program to the board of directors, presenting clear and concise metrics is most effective.

Submitted by ashley.k· Apr 18, 2026Information Security Governance

Question

Which of the following would BEST demonstrate the status of an organization's information security program to the board of directors?

Options

  • AThe information security operations matrix
  • BChanges to information security risks
  • CInformation security program metrics
  • DResults of a recent external audit

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    79% (22)
  • D
    11% (3)

Why each option

To effectively communicate the status of an information security program to the board of directors, presenting clear and concise metrics is most effective.

AThe information security operations matrix

An information security operations matrix details day-to-day operational tasks and responsibilities, which is too granular for a board-level overview.

BChanges to information security risks

While changes to information security risks are important, presenting only changes might lack the comprehensive context of the overall program's status and performance for the board.

CInformation security program metricsCorrect

Information security program metrics provide quantifiable data on the program's performance, achievements, and areas needing improvement, enabling the board to understand the program's effectiveness and make informed decisions. These metrics should align with business objectives and risk appetite.

DResults of a recent external audit

Results of a recent external audit offer a snapshot of compliance or posture at a specific point, but they do not fully encapsulate the ongoing status and effectiveness of the entire security program.

Concept tested: Communicating security program status to leadership

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-55r1.pdf

Topics

#Information Security Program#Board Reporting#Metrics#Governance Oversight

Community Discussion

No community discussion yet for this question.

Full CISM Practice