nerdexam
Isaca

CISM · Question #65

Which of the following is the MOST appropriate metric to demonstrate the effectiveness of information security controls to senior management?

The correct answer is D. Annualized loss resulting from security incidents. The most effective metric to demonstrate information security control effectiveness to senior management is one that quantifies the financial impact of security incidents.

Submitted by thandi_sa· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST appropriate metric to demonstrate the effectiveness of information security controls to senior management?

Options

  • ANumber of security vulnerabilities uncovered with network scans
  • BPercentage of servers patched
  • CDowntime due to malware infections
  • DAnnualized loss resulting from security incidents

How the community answered

(43 responses)
  • A
    16% (7)
  • B
    5% (2)
  • C
    9% (4)
  • D
    70% (30)

Why each option

The most effective metric to demonstrate information security control effectiveness to senior management is one that quantifies the financial impact of security incidents.

ANumber of security vulnerabilities uncovered with network scans

The number of security vulnerabilities is a technical metric that does not directly translate into business impact or financial risk for senior management.

BPercentage of servers patched

The percentage of servers patched is an operational metric indicating security hygiene, but it doesn't directly show the effectiveness of controls in reducing business loss to senior management.

CDowntime due to malware infections

Downtime due to malware infections is a valid operational metric, but annualized loss provides a more comprehensive financial quantification of security control effectiveness over time and in business terms.

DAnnualized loss resulting from security incidentsCorrect

Annualized loss resulting from security incidents is the most appropriate metric for senior management because it quantifies the financial impact of security failures in business terms, allowing them to understand the return on investment for security controls and the overall risk exposure. This metric directly addresses the business value and financial implications of security, which is paramount for executive decision-making.

Concept tested: Information security metrics for management

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Security Metrics#Reporting to Management#Risk Quantification#Control Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice