nerdexam
Isaca

CISM · Question #964

Which of the following is MOST useful to an information security manager when reporting the performance of the information security program to senior management?

The correct answer is B. Number of incidents identified and remediated. Reporting the number of incidents identified and remediated gives senior management a clear, outcome-oriented metric that demonstrates both the program's detection capability and its effectiveness at resolving threats - exactly the kind of operational performance picture…

Submitted by wei.xz· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST useful to an information security manager when reporting the performance of the information security program to senior management?

Options

  • ASystem vulnerability scan results
  • BNumber of incidents identified and remediated
  • CNumber of policy exceptions
  • DResults of an independent security audit

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    78% (18)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Reporting the number of incidents identified and remediated gives senior management a clear, outcome-oriented metric that demonstrates both the program's detection capability and its effectiveness at resolving threats - exactly the kind of operational performance picture executives need to make resource and risk decisions.

Why the distractors fall short:

  • A (Vulnerability scan results) are too technical and granular for a senior audience; they show potential exposure, not program performance over time.
  • C (Policy exceptions) indicate compliance gaps but don't reflect how well the security program is functioning or responding to real threats.
  • D (Independent audit results) are periodic point-in-time assessments, not ongoing performance indicators - useful for governance, but not for regular program reporting.

Memory tip: Think of senior management as wanting a scoreboard, not a playbook - they want to see how many threats were caught and handled (B), not the raw technical details (A), rule-bending counts (C), or an outside referee's one-time verdict (D).

Topics

#Security program performance#Reporting to senior management#Information security metrics#Incident management metrics

Community Discussion

No community discussion yet for this question.

Full CISM Practice