Courseiva

CISM Information Security Governance Practice Question

A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?

⚠ Common exam trap

CISM often tests the ability to distinguish operational metrics from business-impact metrics — candidates pick MTTD or incident counts because they sound security-relevant, but the board-oriented answer must be framed in financial and business-impact terms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security investment vs. loss avoidance

Security investment versus loss avoidance expresses the programme's effectiveness in business terms — how much financial loss was prevented relative to what was spent — which is exactly what a board needs to judge whether the security programme is reducing business impact. It translates technical activity into a cost-benefit narrative that resonates with directors focused on shareholder value and risk appetite. Other metrics are operational and do not directly convey business impact reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security investment vs. loss avoidance

    Why this is correct

    Security investment versus loss avoidance quantifies how much financial damage the programme prevented relative to its cost, directly expressing reduced business impact in monetary terms the board understands, unlike operational metrics such as patch rates or incident counts.

  • ✗

    Number of security incidents

    Why it's wrong here

    A raw incident count reflects activity volume, not effectiveness; incidents can rise while impact falls, or fall while severity grows. Counting incidents suits capacity and trend monitoring, but it cannot demonstrate that the programme reduced the business impact of successful attacks.

  • ✗

    Patch compliance percentage

    Why it's wrong here

    Patch compliance measures operational hygiene, not reduced business impact; a high percentage says nothing about whether losses fell. It is the right metric for tracking vulnerability management process adherence, but the board needs outcome data tied to business consequences.

  • ✗

    Mean time to detect (MTTD)

    Why it's wrong here

    MTTD measures how quickly detection occurs, an internal capability indicator, not whether business impact decreased. It is the correct metric for evaluating detection tooling and SOC responsiveness, but it does not express the financial or operational harm the board cares about.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.