Courseiva

CISM Information Security Governance Practice Question

A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security investment vs. loss avoidance

Option B (Security investment vs. loss avoidance) is correct because it expresses security spending in financial, risk-adjusted terms that directly map to the board's fiduciary concerns about cost-benefit and return on security investment, making it a strategic business metric rather than an operational one. Option D (Mean time to detect, MTTD) is correct because it is a key outcome-oriented metric from the NIST CSF Detect function that quantifies how quickly the organization identifies incidents, giving the board a clear view of detection capability and risk exposure over time. Option A (Number of security staff per business unit) is a resourcing/staffing ratio that is more relevant to operational capacity planning than to board-level risk and value reporting. Option C (Number of firewall rules changed) is a low-level operational change metric that reflects configuration churn, not security posture or business risk. Option E (Average patch deployment time) is a tactical vulnerability-management metric better suited to IT operations or security team dashboards than to the board.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security staff per business unit

    Why it's wrong here

    Headcount ratios describe resourcing structure, not security effectiveness or risk exposure, so they cannot inform board-level governance decisions. Staffing figures suit budget or organisational planning discussions. Board reporting requires outcome metrics such as risk trend, control maturity or breach impact instead.

  • ✓

    Security investment vs. loss avoidance

    Why this is correct

    This metric expresses security in financial terms, letting the board judge whether spend delivers proportionate risk reduction. It satisfies the board-level reporting constraint by linking security to business value, unlike operational measures such as patch latency that lack strategic relevance for directors.

  • ✗

    Number of firewall rules changed

    Why it's wrong here

    Firewall rule change counts are operational configuration activity, not a measure of risk posture or programme effectiveness, so they give the board no decision-useful insight. They belong in change-management or engineering reports. A board dashboard instead needs metrics such as risk reduction, control coverage or incident impact.

  • ✓

    Mean time to detect (MTTD)

    Why this is correct

    MTTD quantifies how quickly the security function identifies intrusions, giving the board a measurable view of detection capability and operational resilience. It satisfies the board-level reporting constraint by summarising programme effectiveness in a single trendable figure rather than raw technical detail.

  • ✗

    Average patch deployment time

    Why it's wrong here

    Average patch deployment time is an operational metric focused on the speed of remediation workflows, not a strategic indicator of residual risk or business impact that a board requires to oversee security governance. It is tempting because it quantifies a tangible IT process efficiency, and would be correct for a technical operations review or an IT manager’s dashboard where tracking patching velocity against service-level agreements is the primary concern.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.