CISM Information Security Governance Practice Question
A CISO is developing a set of metrics to report to the board on the effectiveness of the information security governance program. Which of the following metrics would BEST demonstrate that security governance is aligned with business objectives? (Choose two.)
⚠ Common exam trap
The trap here is selecting operational or financial metrics, such as incident counts or budget percentages, which are easy to measure but do not prove that security governance is aligned with business strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of security initiatives that are directly linked to business strategy objectives.
The two metrics that best demonstrate alignment with business objectives are the percentage of security initiatives linked to business strategy and the percentage of business units represented on the security governance committee. These metrics show that security activities are driven by business goals and that governance includes cross-functional input, ensuring decisions are aligned with organizational needs. They provide the board with tangible evidence of strategic integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Total security budget as a percentage of IT budget.
Why it's wrong here
This metric indicates investment level but not alignment with business objectives. A higher percentage does not necessarily mean better alignment; it could reflect inefficiency or overspending. The board needs to see how security spending translates into business value and strategic support, which this metric alone does not provide.
- ✓
Percentage of security initiatives that are directly linked to business strategy objectives.
Why this is correct
This metric directly measures alignment by showing how many security projects support business goals. A high percentage indicates that security is not operating in isolation but is contributing to the organization's strategic aims. It provides the board with evidence that security investments are prioritized based on business value, which is a core principle of effective governance.
- ✗
Number of security incidents reported to the board.
Why it's wrong here
The number of incidents is an operational metric that indicates threat activity but does not demonstrate alignment with business objectives. A high or low count does not necessarily reflect whether security governance is effective or aligned; it could be due to external factors. The board needs metrics that show how security supports business goals, not just incident frequency.
- ✓
Percentage of business units that have a representative on the security governance committee.
Why this is correct
This metric shows the extent to which business units are engaged in security governance. High participation indicates that security decisions are made collaboratively and consider business needs, which is essential for alignment. It provides the board with assurance that governance is not siloed and that business perspectives are integrated into security oversight.
- ✗
Average time to remediate critical vulnerabilities.
Why it's wrong here
Remediation time is a tactical performance metric that reflects operational efficiency but not strategic alignment with business objectives. While important for risk management, it does not show whether security governance is supporting the business strategy. The board requires metrics that link security activities to business outcomes, not just technical response times.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.