Courseiva

CISM Information Security Program Practice Question

A CISO is establishing a security metrics program to measure the effectiveness of the information security program. The CISO wants to include both key goal indicators (KGIs) and key performance indicators (KPIs). Which of the following are examples of KGIs? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse process metrics (KPIs) with outcome metrics (KGIs); many security metrics are KPIs, so it's easy to misclassify them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Achievement of ISO/IEC 27001 certification within the planned timeframe.

KGIs measure the achievement of strategic goals and outcomes, while KPIs measure the performance of processes. A reduction in successful breaches indicates that the goal of preventing breaches is being met, and achieving ISO/IEC 27001 certification represents the accomplishment of a strategic objective. The other options are process-oriented metrics that track efficiency or activity, not goal attainment. Thus, the two KGIs are the breach reduction and certification achievement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Percentage of critical vulnerabilities remediated within 30 days.

    Why it's wrong here

    This is a KPI because it measures the performance of the vulnerability management process. It indicates how well the process is executing, not whether the ultimate goal (e.g., reducing risk) is achieved. KGIs focus on outcomes, while KPIs focus on process efficiency and effectiveness. This metric is useful for operational oversight but does not directly indicate goal attainment.

  • ✗

    Mean time to detect (MTTD) security incidents.

    Why it's wrong here

    MTTD is a KPI because it measures the performance of the detection process. It indicates how quickly incidents are identified, which is a process efficiency metric. While important, it does not directly measure the achievement of a strategic goal such as reducing risk or preventing breaches. KGIs would be more outcome-oriented, such as a reduction in incident impact.

  • ✗

    Percentage of employees who completed security awareness training.

    Why it's wrong here

    This is a KPI because it measures the performance of the training process. It shows how well the awareness program is being executed but does not indicate whether the goal of reducing human-related incidents is achieved. KGIs would measure outcomes such as a decrease in phishing click rates or reported incidents. This metric is a process indicator.

  • ✓

    Achievement of ISO/IEC 27001 certification within the planned timeframe.

    Why this is correct

    Achieving ISO/IEC 27001 certification is a KGI because it represents the accomplishment of a strategic goal. It is an outcome that the security program aimed to achieve. KGIs are used to track progress toward high-level objectives. Certification demonstrates that the program has met a recognized standard, which is a goal in itself. It is not a process performance measure but a milestone.

  • ✓

    Reduction in the number of successful security breaches year-over-year.

    Why this is correct

    A reduction in successful security breaches is a KGI because it measures the achievement of the goal to prevent breaches. It reflects the outcome of the security program's efforts. KGIs are lagging indicators that show whether strategic objectives are being met. This metric directly indicates the effectiveness of the program in achieving its primary mission.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.