nerdexam
Isaca

CISM · Question #259

Which of the following metrics would provide an accurate measure of an information security program's performance?

The correct answer is B. A combination of qualitative and quantitative trends that enable decision making. Option B is correct because an effective security program measurement framework needs both qualitative context (risk narratives, expert judgment, compliance posture) and quantitative data (incident counts, patch rates, mean time to detect) - and crucially, these must support…

Submitted by packet_pusher· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following metrics would provide an accurate measure of an information security program’s performance?

Options

  • AA collection of qualitative indicators that accurately measure security exceptions
  • BA combination of qualitative and quantitative trends that enable decision making
  • CA collection of quantitative indicators that are compared against industry benchmarks
  • DA single numeric score derived from various measures assigned to the security program

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    89% (34)
  • C
    3% (1)
  • D
    5% (2)

Explanation

Option B is correct because an effective security program measurement framework needs both qualitative context (risk narratives, expert judgment, compliance posture) and quantitative data (incident counts, patch rates, mean time to detect) - and crucially, these must support trends over time that drive actual decisions rather than just reporting status.

Why the distractors fail:

  • A fails because relying solely on qualitative indicators lacks the numerical rigor needed to objectively demonstrate progress or regression; qualitative alone is too subjective for accountability.
  • C fails because purely quantitative indicators compared to industry benchmarks tell you how you rank externally but don't necessarily reflect your program's trajectory or support internal decision-making.
  • D fails because collapsing everything into a single score loses granularity - a composite number can hide critical weaknesses behind strong scores in other areas, masking real risk.

Memory tip: Think "CISO briefing" - a good CISO needs stories (qualitative) backed by numbers (quantitative), presented as trends so the board can make decisions. A single score is a dashboard vanity metric; benchmarks alone tell you nothing about where you're headed.

Topics

#Program Performance Measurement#Security Metrics#Qualitative & Quantitative Data#Decision Support

Community Discussion

No community discussion yet for this question.

Full CISM Practice