nerdexam
Isaca

CISM · Question #608

Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?

The correct answer is A. Program metrics. Program metrics provide measurable data that reflect how well information security governance objectives are being achieved, enabling the organization to assess effectiveness and drive continuous improvement.

Submitted by yuriko_h· Apr 18, 2026Information Security Governance

Question

Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?

Options

  • AProgram metrics
  • BRisk register
  • CKey risk indicators (KRIs)
  • DSecurity strategy

How the community answered

(24 responses)
  • A
    75% (18)
  • B
    4% (1)
  • C
    8% (2)
  • D
    13% (3)

Explanation

Program metrics provide measurable data that reflect how well information security governance objectives are being achieved, enabling the organization to assess effectiveness and drive continuous improvement.

Topics

#Information Security Governance#Performance Measurement#Security Program Metrics#Effectiveness Assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice