nerdexam
Isaca

CISM · Question #822

Which of the following is the BEST source of data for measuring the effectiveness of an organization's information security program?

The correct answer is B. Key performance indicators (KPIs). Key performance indicators (KPIs) are specifically designed to measure performance against defined program objectives, making them the best source for evaluating how effectively the security program is achieving its goals. KRIs (C) are predictive - they signal potential future…

Submitted by minji_kr· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the BEST source of data for measuring the effectiveness of an organization's information security program?

Options

  • AIncident response test results
  • BKey performance indicators (KPIs)
  • CKey risk indicators (KRIs)
  • DRisk assessments

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • C
    3% (1)

Explanation

Key performance indicators (KPIs) are specifically designed to measure performance against defined program objectives, making them the best source for evaluating how effectively the security program is achieving its goals. KRIs (C) are predictive - they signal potential future risk events, not past performance. Risk assessments (D) are point-in-time snapshots of the threat landscape, not ongoing performance measures. Incident response test results (A) capture only one narrow dimension of the program. KPIs provide a broad, ongoing, goal-oriented measurement framework that directly answers the question 'Is our program working?'

Topics

#Information Security Program Effectiveness#KPIs#Security Metrics#Program Measurement

Community Discussion

No community discussion yet for this question.

Full CISM Practice