nerdexam
Isaca

CISM · Question #120

What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?

The correct answer is B. Aligning the metrics with the organizational culture. When establishing metrics for a security strategy committee, it is most important to align them with the organizational culture to ensure they are relevant, understood, and supported.

Submitted by yuriko_h· Apr 18, 2026Information Security Governance

Question

What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?

Options

  • ABenchmarking the expected value of the metrics against industry standards
  • BAligning the metrics with the organizational culture
  • CAgreeing on baseline values for the metrics
  • DDeveloping a dashboard for communicating the metrics

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    71% (17)
  • C
    4% (1)
  • D
    17% (4)

Why each option

When establishing metrics for a security strategy committee, it is most important to align them with the organizational culture to ensure they are relevant, understood, and supported.

ABenchmarking the expected value of the metrics against industry standards

Benchmarking is useful for context but is secondary to ensuring the metrics are culturally relevant and understood by the specific committee.

BAligning the metrics with the organizational cultureCorrect

Metrics must be framed and presented in a way that resonates with the organizational culture and the committee's priorities, using language and concepts they understand and value. This alignment ensures the metrics are seen as relevant to business objectives and foster better engagement and decision-making by the strategy committee.

CAgreeing on baseline values for the metrics

Agreeing on baseline values is important for measuring progress, but the foundational step is ensuring the metrics themselves are meaningful within the organizational context.

DDeveloping a dashboard for communicating the metrics

A dashboard is a tool for communication, not the most important consideration in *establishing* the metrics themselves; the content is more critical than the format.

Concept tested: Security metrics reporting effectiveness

Topics

#Security Metrics#Strategic Reporting#Organizational Culture#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice