CISM · Question #120
What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?
The correct answer is B. Aligning the metrics with the organizational culture. When establishing metrics for a security strategy committee, it is most important to align them with the organizational culture to ensure they are relevant, understood, and supported.
Question
What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?
Options
- ABenchmarking the expected value of the metrics against industry standards
- BAligning the metrics with the organizational culture
- CAgreeing on baseline values for the metrics
- DDeveloping a dashboard for communicating the metrics
How the community answered
(24 responses)- A8% (2)
- B71% (17)
- C4% (1)
- D17% (4)
Why each option
When establishing metrics for a security strategy committee, it is most important to align them with the organizational culture to ensure they are relevant, understood, and supported.
Benchmarking is useful for context but is secondary to ensuring the metrics are culturally relevant and understood by the specific committee.
Metrics must be framed and presented in a way that resonates with the organizational culture and the committee's priorities, using language and concepts they understand and value. This alignment ensures the metrics are seen as relevant to business objectives and foster better engagement and decision-making by the strategy committee.
Agreeing on baseline values is important for measuring progress, but the foundational step is ensuring the metrics themselves are meaningful within the organizational context.
A dashboard is a tool for communication, not the most important consideration in *establishing* the metrics themselves; the content is more critical than the format.
Concept tested: Security metrics reporting effectiveness
Topics
Community Discussion
No community discussion yet for this question.