nerdexam
Isaca

CISM · Question #272

Which of the following is MOST appropriate to report to management when addressing concerns with the effectiveness of the organization's information security program?

The correct answer is C. Impact of information security incidents on business processes. When reporting to management on the effectiveness of the information security program, the most compelling and business-relevant metric is how security incidents actually affect business operations - this speaks directly to whether the program is succeeding at protecting what mat

Submitted by katya_ua· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST appropriate to report to management when addressing concerns with the effectiveness of the organization's information security program?

Options

  • ALevel of compliance with information security policies
  • BPerformance metrics related to information security awareness training
  • CImpact of information security incidents on business processes
  • DResults of assessments for implemented information security controls

How the community answered

(45 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    80% (36)
  • D
    11% (5)

Explanation

When reporting to management on the effectiveness of the information security program, the most compelling and business-relevant metric is how security incidents actually affect business operations - this speaks directly to whether the program is succeeding at protecting what matters most. Options A (policy compliance) and D (control assessment results) are internally-focused technical measures that tell you what was done, not whether the program is working. Option B (awareness training metrics) is too narrow - it reflects one component of the program rather than overall effectiveness. Options A, B, and D are all inputs or activities; management needs outcomes.

Memory tip: Think of the acronym IMPACT - management cares about Impact, not just activities. If you can't tie your security report to a business consequence, it belongs in a technical report, not an executive briefing.

Topics

#Reporting to management#Program effectiveness#Business impact#Information security program

Community Discussion

No community discussion yet for this question.

Full CISM Practice