Courseiva

CISM Information Security Programme Practice Question

A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?

⚠ Common exam trap

CISM often tests the distinction between activity/input metrics (tools, headcount, budget) and outcome/effectiveness metrics (MTTD, MTTR, breaches) — candidates pick busy-sounding operational stats that do not answer the board's risk question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to detect (MTTD), mean time to respond (MTTR), and number of breaches

MTTD, MTTR, and number of breaches directly measure how quickly the security program detects and contains incidents and how often it fails, which is what a board needs to judge effectiveness. These are outcome-oriented metrics tied to risk, not activity counts. They translate technical operations into business-relevant resilience indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security architects, SOC analyst headcount, and security tool count

    Why it's wrong here

    Headcount and tool counts are resource inputs, revealing nothing about whether controls work or risk is falling. Effectiveness requires outcome and risk metrics. These figures would be appropriate for capacity planning or budget justification, not for demonstrating security programme value to a board.

  • ✓

    Mean time to detect (MTTD), mean time to respond (MTTR), and number of breaches

    Why this is correct

    MTTD and MTTR measure detection and response capability, while breach count shows realised impact, together covering the programme's operational effectiveness. This combination gives the board outcome and capability insight rather than raw technical volume, satisfying the meaningful overview requirement.

  • ✗

    Number of security incidents, percentage of systems patched, and security awareness training completion rate

    Why it's wrong here

    Incident counts, patch percentages and training completion are operational activity measures; they show effort, not whether risk is being reduced or the programme is effective. Board dashboards need outcome and risk-trend metrics. This combination would suit a tactical operations review rather than strategic effectiveness reporting.

  • ✗

    Phishing click rate, number of vendor assessments completed, and security budget spent

    Why it's wrong here

    Phishing click rate, vendor assessments and budget spent mix one behavioural indicator with activity and financial inputs, giving no view of risk reduction or control effectiveness. Boards need outcome-oriented measures. This set would fit a departmental activity report, not a strategic programme effectiveness dashboard.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.