CISM · Question #134
Which of the following is MOST important to define when creating information security management metrics?
The correct answer is B. Objectives. Metrics exist to measure progress toward goals. Without clearly defined objectives, metrics are arbitrary and unmeaningful-you cannot know what to measure, what a 'good' result looks like, or whether performance is improving. Objectives answer the question: 'What are we trying…
Question
Which of the following is MOST important to define when creating information security management metrics?
Options
- ABudget
- BObjectives
- CPolicy
- DBenchmarks
How the community answered
(20 responses)- B95% (19)
- D5% (1)
Explanation
Metrics exist to measure progress toward goals. Without clearly defined objectives, metrics are arbitrary and unmeaningful-you cannot know what to measure, what a 'good' result looks like, or whether performance is improving. Objectives answer the question: 'What are we trying to achieve?' and every metric should map directly to an objective. Budget (A) determines resource availability but doesn't define what you measure. Policy (C) sets rules and requirements that metrics may monitor, but policy flows from objectives. Benchmarks (D) provide comparative context but are useless without first knowing what objective you are benchmarking against.
Topics
Community Discussion
No community discussion yet for this question.