Courseiva

CISM Information Security Program Practice Question

A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)

⚠ Common exam trap

The trap here is selecting activity or input metrics like number of policies or budget percentage, which measure effort or resources rather than the effectiveness of security processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of critical vulnerabilities remediated within defined timeframes.

The correct answers are mean time to detect (MTTD) and percentage of critical vulnerabilities remediated within defined timeframes. Both are performance-oriented metrics that measure the speed and effectiveness of key security processes, providing insight into how well the program reduces risk. They are actionable and can be trended over time to show improvement or deterioration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security policies approved by management.

    Why it's wrong here

    The number of approved policies is a compliance or activity metric, not a performance indicator. It shows that documentation exists but does not measure whether policies are effective or followed. Policies alone do not reduce risk; their implementation and enforcement matter. Thus, this is not a strong KPI for effectiveness.

  • ✓

    Percentage of critical vulnerabilities remediated within defined timeframes.

    Why this is correct

    This KPI measures how well the organization manages vulnerabilities on critical assets, directly reflecting risk reduction. Meeting remediation timeframes indicates an effective vulnerability management process. It is a performance measure because it tracks the speed and completeness of a key security activity, and can be tied to risk tolerance.

  • ✗

    Annual security budget as a percentage of IT budget.

    Why it's wrong here

    Budget allocation is an input metric, not a performance indicator. It shows investment level but not how well the investment is used. A high budget does not guarantee effective security, and a low budget does not necessarily mean poor security. Therefore, it is not a direct measure of program effectiveness.

  • ✗

    Total number of security tools deployed.

    Why it's wrong here

    The number of tools is an inventory metric, not a performance measure. More tools do not necessarily mean better security; they can increase complexity and cost. This metric does not indicate whether the tools are used effectively or if they contribute to risk reduction, so it is not suitable as a KPI for program effectiveness.

  • ✓

    Mean time to detect (MTTD) security incidents.

    Why this is correct

    MTTD measures how quickly the security team identifies incidents, which is a direct indicator of detection capability. A lower MTTD means threats are discovered sooner, reducing potential impact. This KPI is actionable and can be improved through monitoring and automation, making it a valuable measure of program effectiveness.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.