Courseiva

CISM Information Security Governance Practice Question

A CISO is developing a set of key risk indicators (KRIs) to monitor information security governance effectiveness. The CISO wants to ensure that the KRIs are actionable and aligned with business objectives. Which two characteristics are MOST important for effective KRIs? (Choose two.)

⚠ Common exam trap

The trap here is selecting characteristics that seem efficient or common, such as annual updates or sole reliance on benchmarks, which actually undermine the actionability and relevance of KRIs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They are measurable and quantifiable.

Effective KRIs are measurable and quantifiable, enabling objective tracking, and are directly tied to business objectives and risk appetite, ensuring relevance to strategic goals. These characteristics allow the CISO to monitor governance effectiveness and make informed decisions that align security with business needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They are updated on an annual basis to reduce reporting overhead.

    Why it's wrong here

    Annual updates are too infrequent for effective risk monitoring. KRIs should be reviewed and updated regularly, often quarterly or more frequently, to reflect changing risk conditions. Infrequent updates can lead to outdated indicators that fail to support timely decision-making.

  • ✗

    They are based solely on industry benchmarks.

    Why it's wrong here

    While benchmarks provide context, KRIs based solely on industry averages may not reflect the organization's specific risk profile, objectives, or appetite. Effective KRIs must be tailored to the organization's unique environment to be actionable and relevant.

  • ✓

    They are measurable and quantifiable.

    Why this is correct

    Effective KRIs must be measurable and quantifiable to allow objective tracking and trend analysis. Without a numerical basis, it is impossible to determine whether risk is increasing or decreasing, making it difficult to take timely action and demonstrate governance effectiveness to stakeholders.

  • ✓

    They are directly tied to business objectives and risk appetite.

    Why this is correct

    KRIs must reflect the organization's business objectives and risk appetite to ensure that security efforts support strategic goals. This alignment enables the CISO to communicate risk in business terms and prioritize resources on the most relevant threats, which is essential for governance.

  • ✗

    They are kept confidential and shared only with the security team.

    Why it's wrong here

    Restricting KRIs to the security team limits their usefulness for governance. KRIs should be communicated to relevant stakeholders, including business leaders and the board, to inform risk-based decisions and demonstrate accountability. Confidentiality may be needed for sensitive details, but broad sharing of aggregated indicators is essential.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.