nerdexam
Isaca

CISM · Question #257

Which of the following is the MOST important characteristic of an effective information security metric?

The correct answer is A. The metric expresses residual risk relative to risk tolerance. The most important characteristic of a security metric is that it conveys actionable, decision-relevant information. Expressing residual risk (the risk remaining after controls are applied) relative to risk tolerance directly answers the question executives care about most…

Submitted by katya_ua· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the MOST important characteristic of an effective information security metric?

Options

  • AThe metric expresses residual risk relative to risk tolerance.
  • BThe metric is frequently reported to senior management.
  • CThe metric directly maps to an industry risk management framework.
  • DThe metric compares the organization's inherent risk against its risk appetite.

How the community answered

(22 responses)
  • A
    77% (17)
  • B
    5% (1)
  • C
    14% (3)
  • D
    5% (1)

Explanation

The most important characteristic of a security metric is that it conveys actionable, decision-relevant information. Expressing residual risk (the risk remaining after controls are applied) relative to risk tolerance directly answers the question executives care about most: 'Are we within acceptable risk limits?' Reporting frequency (B) is a delivery characteristic, not a quality characteristic. Mapping to an industry framework (C) aids comparability but is not inherently meaningful without organizational context. Comparing inherent risk to risk appetite (D) ignores the effect of existing controls, making it less meaningful than residual risk, which reflects actual exposure.

Topics

#Information Security Metrics#Risk Management#Residual Risk#Risk Tolerance

Community Discussion

No community discussion yet for this question.

Full CISM Practice