Courseiva

CISM Information Security Governance Practice Question

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

⚠ Common exam trap

CISM often tests the difference between operational metrics and strategic/board-level metrics — candidates pick patch compliance or training completion because they sound security-relevant, but boards need outcome and financial-impact measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to detect (MTTD) and mean time to respond (MTTR)

Option B (MTTD and MTTR) is correct because these metrics quantify how quickly the security operations function detects and contains incidents, directly expressing the programme's operational effectiveness in business-relevant terms the board can track over time. Option D (security investment vs. loss avoidance) is correct because it frames security spending against avoided financial impact, giving the board a cost-benefit view of risk reduction that supports governance and funding decisions. The unmarked options are too tactical or activity-based for board-level reporting: firewall rule changes (A) and patch compliance percentage (E) are operational/technical metrics, and training completion counts (C) measure activity rather than outcome or risk reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of firewall rules changed

    Why it's wrong here

    Firewall rule changes are an operational configuration count, conveying no risk posture or control effectiveness to a board. Such change-volume data suits engineering capacity planning or audit trails. Board reporting instead needs metrics tying security investment to business risk reduction.

  • ✓

    Mean time to detect (MTTD) and mean time to respond (MTTR)

    Why this is correct

    MTTD and MTTR measure how quickly the security programme detects and contains incidents, translating technical operations into resilience outcomes. These satisfy the board-level reporting constraint by conveying programme effectiveness in business-relevant terms rather than raw alert volumes.

  • ✗

    Number of employees who completed security training

    Why it's wrong here

    Training completion counts measure awareness activity uptake, not whether the security programme reduces risk or changes behaviour. This figure is appropriate for compliance tracking or awareness programme management. Board-level reporting instead demands outcome-oriented metrics aligned to business risk and strategy.

  • ✓

    Security investment vs. loss avoidance

    Why this is correct

    Comparing security investment against avoided losses expresses programme value in financial terms, the language boards use for governance decisions. This satisfies the board-level reporting constraint by demonstrating cost-effectiveness rather than operational detail such as patch counts or vulnerability totals.

  • ✗

    Patch compliance percentage

    Why it's wrong here

    Patch compliance percentage is a tactical vulnerability-management measure describing endpoint hygiene, not programme effectiveness in business terms. It belongs in operational or technical risk reporting to security management. Boards require metrics linking security posture to organisational risk and strategic objectives.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.