CISM Information Security Program Practice Question
A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)
⚠ Common exam trap
The trap here is selecting activity or input metrics like number of policies or budget percentage, which measure effort or resources rather than the effectiveness of security processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of critical vulnerabilities remediated within defined timeframes.
The correct answers are mean time to detect (MTTD) and percentage of critical vulnerabilities remediated within defined timeframes. Both are performance-oriented metrics that measure the speed and effectiveness of key security processes, providing insight into how well the program reduces risk. They are actionable and can be trended over time to show improvement or deterioration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security policies approved by management.
Why it's wrong here
The number of approved policies is a compliance or activity metric, not a performance indicator. It shows that documentation exists but does not measure whether policies are effective or followed. Policies alone do not reduce risk; their implementation and enforcement matter. Thus, this is not a strong KPI for effectiveness.
- ✓
Percentage of critical vulnerabilities remediated within defined timeframes.
Why this is correct
This KPI measures how well the organization manages vulnerabilities on critical assets, directly reflecting risk reduction. Meeting remediation timeframes indicates an effective vulnerability management process. It is a performance measure because it tracks the speed and completeness of a key security activity, and can be tied to risk tolerance.
- ✗
Annual security budget as a percentage of IT budget.
Why it's wrong here
Budget allocation is an input metric, not a performance indicator. It shows investment level but not how well the investment is used. A high budget does not guarantee effective security, and a low budget does not necessarily mean poor security. Therefore, it is not a direct measure of program effectiveness.
- ✗
Total number of security tools deployed.
Why it's wrong here
The number of tools is an inventory metric, not a performance measure. More tools do not necessarily mean better security; they can increase complexity and cost. This metric does not indicate whether the tools are used effectively or if they contribute to risk reduction, so it is not suitable as a KPI for program effectiveness.
- ✓
Mean time to detect (MTTD) security incidents.
Why this is correct
MTTD measures how quickly the security team identifies incidents, which is a direct indicator of detection capability. A lower MTTD means threats are discovered sooner, reducing potential impact. This KPI is actionable and can be improved through monitoring and automation, making it a valuable measure of program effectiveness.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.