Courseiva

CISM Information Security Program Practice Question

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to the business and driving continuous improvement. Which of the following are the MOST appropriate key performance indicators (KPIs) for the information security program? (Choose two.)

⚠ Common exam trap

The trap here is selecting activity-based metrics like policy approvals or training completion, which measure effort rather than effectiveness, instead of outcome-based KPIs that demonstrate risk reduction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of critical systems covered by the vulnerability management program.

The most appropriate KPIs are those that measure the effectiveness of security controls and processes in reducing risk. The percentage of critical systems covered by vulnerability management and mean time to remediate critical vulnerabilities both directly reflect the program's ability to manage a key risk area. They are actionable, quantifiable, and demonstrate value to the business by showing risk reduction over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security policies approved by the steering committee.

    Why it's wrong here

    While policy approval is a governance activity, the number of policies approved is not a meaningful KPI for program performance. It measures activity rather than effectiveness or risk reduction. A program could have many policies but poor compliance or weak controls. This metric does not indicate whether the program is achieving its objectives or improving security posture. It is more of a governance metric than a performance indicator.

  • ✓

    Percentage of critical systems covered by the vulnerability management program.

    Why this is correct

    This KPI measures the coverage and effectiveness of a core security control. A high percentage indicates that the program is systematically identifying and addressing vulnerabilities across critical assets, which directly reduces risk. It is a performance indicator that can drive improvement by highlighting gaps in coverage. It also demonstrates to the business that the program is proactively managing a key risk area, making it a valuable KPI.

  • ✗

    Total number of security incidents reported by employees.

    Why it's wrong here

    The total number of reported incidents can be influenced by many factors, including awareness and reporting culture. A high number could indicate either a real increase in incidents or better reporting. Without context, it is not a reliable KPI for program effectiveness. It does not directly measure the program's ability to prevent, detect, or respond to incidents in a way that demonstrates value or drives improvement.

  • ✗

    Percentage of employees who completed security awareness training.

    Why it's wrong here

    Completion rate is a compliance metric, not a performance indicator. It shows that training was delivered but does not measure whether behavior changed or risk was reduced. Employees can complete training without retaining knowledge or applying it. While important for compliance, it does not demonstrate the program's effectiveness in reducing risk or achieving security objectives, so it is less appropriate as a KPI.

  • ✓

    Mean time to remediate critical vulnerabilities.

    Why this is correct

    This KPI measures the efficiency of the vulnerability management process and the program's ability to reduce exposure to critical risks. A shorter mean time indicates a more responsive and effective program. It is actionable and can drive improvements in incident response and patch management. It also provides a clear metric that business leaders can understand in terms of risk reduction over time.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.