Isaca
CISM · Question #608
Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?
The correct answer is A. Program metrics. Program metrics provide measurable data that reflect how well information security governance objectives are being achieved, enabling the organization to assess effectiveness and drive continuous improvement.
Submitted by yuriko_h· Apr 18, 2026Information Security Governance
Question
Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?
Options
- AProgram metrics
- BRisk register
- CKey risk indicators (KRIs)
- DSecurity strategy
How the community answered
(24 responses)- A75% (18)
- B4% (1)
- C8% (2)
- D13% (3)
Explanation
Program metrics provide measurable data that reflect how well information security governance objectives are being achieved, enabling the organization to assess effectiveness and drive continuous improvement.
Topics
#Information Security Governance#Performance Measurement#Security Program Metrics#Effectiveness Assessment
Community Discussion
No community discussion yet for this question.