When the board of directors requests a report on the current IT risk posture, which metric is most effective for demonstrating alignment between risk appetite and investment?
Trap 1: Number of open high-severity security patches.
This is a tactical operational metric, not a strategic governance metric.
Trap 2: Average response time for IT service desk tickets.
This is a performance indicator, not a risk-governance metric.
Trap 3: Historical count of phishing emails blocked by the email gateway.
This is a measure of operational threat volume, not strategic risk posture.
- A
Number of open high-severity security patches.
Why wrong: This is a tactical operational metric, not a strategic governance metric.
- B
Average response time for IT service desk tickets.
Why wrong: This is a performance indicator, not a risk-governance metric.
- C
Total dollar value of IT capital expenditure.
This shows how resources are allocated to mitigate risks that exceed established appetite levels.
- D
Historical count of phishing emails blocked by the email gateway.
Why wrong: This is a measure of operational threat volume, not strategic risk posture.