CISM Information Security Program Practice Question
A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to senior management. Which of the following are characteristics of effective security metrics? (Choose two.)
⚠ Common exam trap
The trap here is assuming that incident counts or technical vulnerabilities are sufficient, when effective metrics must align with business goals and be consistently measured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are directly linked to business objectives.
Effective security metrics are directly linked to business objectives and are consistently measurable over time. These characteristics ensure that metrics demonstrate how security supports the organization's strategic goals and allow for trend analysis and benchmarking. They provide senior management with meaningful information to make informed decisions about the security program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are focused on technical vulnerabilities.
Why it's wrong here
Focusing solely on technical vulnerabilities provides a narrow view of security performance. Senior management needs a broader perspective that includes risk, compliance, and business impact. Technical metrics are useful for operational teams but do not convey the overall effectiveness of the security program in managing risks to the organization.
- ✗
They are based on the number of security incidents.
Why it's wrong here
While incident counts can be useful, they are often lagging indicators and do not necessarily reflect the effectiveness of the security program. A low incident count might be due to underreporting or a lack of detection. Metrics should focus on risk reduction and control effectiveness, not just raw incident numbers, to provide meaningful insights.
- ✓
They are directly linked to business objectives.
Why this is correct
Effective security metrics must align with business objectives to demonstrate value. For example, a metric showing reduced downtime from security incidents directly supports business continuity goals. When metrics are tied to business outcomes, senior management can see how security contributes to the bottom line, making it easier to justify investments and prioritize initiatives.
- ✓
They are consistently measurable over time.
Why this is correct
Consistency is crucial for tracking progress and identifying trends. Metrics must be defined clearly and measured using the same methodology over time to allow for meaningful comparison. Inconsistent measurement can lead to misleading conclusions and undermine confidence in the program's performance. Consistent metrics enable benchmarking and continuous improvement.
- ✗
They are updated in real time.
Why it's wrong here
Real-time updates can be valuable for operational monitoring, but they are not a requirement for effective strategic metrics. Many key performance indicators are reported monthly or quarterly to show trends. Real-time data may be noisy and not suitable for executive reporting, which focuses on strategic insights rather than immediate operational status.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.