CISM Information Security Programme Practice Question
A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?
⚠ Common exam trap
CISM often tests the distinction between activity/input metrics (tools, headcount, budget) and outcome/effectiveness metrics (MTTD, MTTR, breaches) — candidates pick busy-sounding operational stats that do not answer the board's risk question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to detect (MTTD), mean time to respond (MTTR), and number of breaches
MTTD, MTTR, and number of breaches directly measure how quickly the security program detects and contains incidents and how often it fails, which is what a board needs to judge effectiveness. These are outcome-oriented metrics tied to risk, not activity counts. They translate technical operations into business-relevant resilience indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security architects, SOC analyst headcount, and security tool count
Why it's wrong here
Headcount and tool counts are resource inputs, revealing nothing about whether controls work or risk is falling. Effectiveness requires outcome and risk metrics. These figures would be appropriate for capacity planning or budget justification, not for demonstrating security programme value to a board.
- ✓
Mean time to detect (MTTD), mean time to respond (MTTR), and number of breaches
Why this is correct
MTTD and MTTR measure detection and response capability, while breach count shows realised impact, together covering the programme's operational effectiveness. This combination gives the board outcome and capability insight rather than raw technical volume, satisfying the meaningful overview requirement.
- ✗
Number of security incidents, percentage of systems patched, and security awareness training completion rate
Why it's wrong here
Incident counts, patch percentages and training completion are operational activity measures; they show effort, not whether risk is being reduced or the programme is effective. Board dashboards need outcome and risk-trend metrics. This combination would suit a tactical operations review rather than strategic effectiveness reporting.
- ✗
Phishing click rate, number of vendor assessments completed, and security budget spent
Why it's wrong here
Phishing click rate, vendor assessments and budget spent mix one behavioural indicator with activity and financial inputs, giving no view of risk reduction or control effectiveness. Boards need outcome-oriented measures. This set would fit a departmental activity report, not a strategic programme effectiveness dashboard.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.