nerdexam
Isaca

CISM · Question #722

When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:

The correct answer is C. consider the organization's business strategy.. Metrics for an information security program must ultimately demonstrate how well security supports what the organization is trying to achieve as a business - without that alignment, metrics become internally focused vanity measures that don't resonate with executives or justify r

Submitted by jordan8· Apr 18, 2026Information Security Governance

Question

When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:

Options

  • Aconsider the strategic objectives of the program.
  • Bleverage industry benchmarks.
  • Cconsider the organization's business strategy.
  • Didentify the program's risk and compensating controls.

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    93% (25)
  • D
    4% (1)

Explanation

Metrics for an information security program must ultimately demonstrate how well security supports what the organization is trying to achieve as a business - without that alignment, metrics become internally focused vanity measures that don't resonate with executives or justify resource decisions.

  • A is wrong because the program's strategic objectives should themselves be derived from the business strategy, making this a downstream consideration, not the primary driver.
  • B is wrong because industry benchmarks tell you how you compare to peers, not whether your program is effective for your specific organization's goals and risk appetite.
  • D is wrong because identifying risks and compensating controls is a risk management activity - useful input, but not the anchor for selecting monitoring metrics.

Memory tip: Think of the security program as a service to the business. Just as a sales department measures success by revenue (a business goal), security metrics must map to business outcomes. Ask: "Does this metric show whether security is enabling the business strategy?" - if yes, it belongs.

Topics

#Security Metrics#Business Alignment#Program Effectiveness#Strategic Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice