nerdexam
Isaca

CISM · Question #134

Which of the following is MOST important to define when creating information security management metrics?

The correct answer is B. Objectives. Metrics exist to measure progress toward goals. Without clearly defined objectives, metrics are arbitrary and unmeaningful-you cannot know what to measure, what a 'good' result looks like, or whether performance is improving. Objectives answer the question: 'What are we trying…

Submitted by devops_kid· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST important to define when creating information security management metrics?

Options

  • ABudget
  • BObjectives
  • CPolicy
  • DBenchmarks

How the community answered

(20 responses)
  • B
    95% (19)
  • D
    5% (1)

Explanation

Metrics exist to measure progress toward goals. Without clearly defined objectives, metrics are arbitrary and unmeaningful-you cannot know what to measure, what a 'good' result looks like, or whether performance is improving. Objectives answer the question: 'What are we trying to achieve?' and every metric should map directly to an objective. Budget (A) determines resource availability but doesn't define what you measure. Policy (C) sets rules and requirements that metrics may monitor, but policy flows from objectives. Benchmarks (D) provide comparative context but are useless without first knowing what objective you are benchmarking against.

Topics

#Information Security Metrics#Performance Measurement#Strategic Objectives#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice