CISM · Question #272
Which of the following is MOST appropriate to report to management when addressing concerns with the effectiveness of the organization's information security program?
The correct answer is C. Impact of information security incidents on business processes. When reporting to management on the effectiveness of the information security program, the most compelling and business-relevant metric is how security incidents actually affect business operations - this speaks directly to whether the program is succeeding at protecting what mat
Question
Which of the following is MOST appropriate to report to management when addressing concerns with the effectiveness of the organization's information security program?
Options
- ALevel of compliance with information security policies
- BPerformance metrics related to information security awareness training
- CImpact of information security incidents on business processes
- DResults of assessments for implemented information security controls
How the community answered
(45 responses)- A7% (3)
- B2% (1)
- C80% (36)
- D11% (5)
Explanation
When reporting to management on the effectiveness of the information security program, the most compelling and business-relevant metric is how security incidents actually affect business operations - this speaks directly to whether the program is succeeding at protecting what matters most. Options A (policy compliance) and D (control assessment results) are internally-focused technical measures that tell you what was done, not whether the program is working. Option B (awareness training metrics) is too narrow - it reflects one component of the program rather than overall effectiveness. Options A, B, and D are all inputs or activities; management needs outcomes.
Memory tip: Think of the acronym IMPACT - management cares about Impact, not just activities. If you can't tie your security report to a business consequence, it belongs in a technical report, not an executive briefing.
Topics
Community Discussion
No community discussion yet for this question.