nerdexam
Isaca

CISM · Question #2

When establishing metrics for an information security program, the BEST approach is to identify indicators that:

The correct answer is D. demonstrate the effectiveness of the security program. The best approach to establishing information security metrics is to identify indicators that clearly demonstrate the overall effectiveness of the security program.

Submitted by jaden.t· Apr 18, 2026Information Security Program Development and Management

Question

When establishing metrics for an information security program, the BEST approach is to identify indicators that:

Options

  • Asupport major information security initiatives.
  • Breflect the corporate risk culture.
  • Creduce information security program spending.
  • Ddemonstrate the effectiveness of the security program.

How the community answered

(34 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    94% (32)

Why each option

The best approach to establishing information security metrics is to identify indicators that clearly demonstrate the overall effectiveness of the security program.

Asupport major information security initiatives.

While supporting major initiatives is a good outcome, it's a subset of demonstrating overall program effectiveness and not the primary focus for all metrics.

Breflect the corporate risk culture.

Reflecting corporate risk culture is important for alignment, but metrics should go beyond culture to objectively measure security performance.

Creduce information security program spending.

Reducing program spending might be a goal, but it's not the primary purpose of security metrics, which should focus on security posture and effectiveness.

Ddemonstrate the effectiveness of the security program.Correct

Metrics should primarily measure how well the security program achieves its objectives, such as reducing risk, protecting assets, and ensuring compliance, thereby demonstrating its effectiveness to stakeholders. This allows for data-driven decision-making and continuous improvement of security controls and strategies.

Concept tested: Information security program metrics

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-55r1.pdf

Topics

#Security program metrics#Program effectiveness#Performance measurement#Program management

Community Discussion

No community discussion yet for this question.

Full CISM Practice