CISM · Question #259
Which of the following metrics would provide an accurate measure of an information security program's performance?
The correct answer is B. A combination of qualitative and quantitative trends that enable decision making. Option B is correct because an effective security program measurement framework needs both qualitative context (risk narratives, expert judgment, compliance posture) and quantitative data (incident counts, patch rates, mean time to detect) - and crucially, these must support…
Question
Which of the following metrics would provide an accurate measure of an information security program’s performance?
Options
- AA collection of qualitative indicators that accurately measure security exceptions
- BA combination of qualitative and quantitative trends that enable decision making
- CA collection of quantitative indicators that are compared against industry benchmarks
- DA single numeric score derived from various measures assigned to the security program
How the community answered
(38 responses)- A3% (1)
- B89% (34)
- C3% (1)
- D5% (2)
Explanation
Option B is correct because an effective security program measurement framework needs both qualitative context (risk narratives, expert judgment, compliance posture) and quantitative data (incident counts, patch rates, mean time to detect) - and crucially, these must support trends over time that drive actual decisions rather than just reporting status.
Why the distractors fail:
- A fails because relying solely on qualitative indicators lacks the numerical rigor needed to objectively demonstrate progress or regression; qualitative alone is too subjective for accountability.
- C fails because purely quantitative indicators compared to industry benchmarks tell you how you rank externally but don't necessarily reflect your program's trajectory or support internal decision-making.
- D fails because collapsing everything into a single score loses granularity - a composite number can hide critical weaknesses behind strong scores in other areas, masking real risk.
Memory tip: Think "CISO briefing" - a good CISO needs stories (qualitative) backed by numbers (quantitative), presented as trends so the board can make decisions. A single score is a dashboard vanity metric; benchmarks alone tell you nothing about where you're headed.
Topics
Community Discussion
No community discussion yet for this question.