CISM Information Security Governance Practice Question
A CISO is reviewing the information security strategy and needs to ensure that security investments are justified in business terms. The CFO has requested that each security initiative be tied to a financial metric that reflects potential loss from cyber events. Which approach is MOST appropriate for the CISO to use?
⚠ Common exam trap
Many exam-takers confuse operational metrics such as incident counts or training completion with financial metrics that express risk in monetary terms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Calculate the annualized loss expectancy (ALE) for each initiative based on risk assessment data.
Using annualized loss expectancy translates risk into monetary terms, enabling direct comparison of security initiatives against expected financial loss. This aligns security governance with business objectives and provides the CFO with a quantifiable basis for investment decisions, which is a core CISM principle for integrating security into business strategy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Benchmark the organization's security budget against industry peers.
Why it's wrong here
Peer benchmarking provides context but does not calculate financial loss potential for specific initiatives. It may show relative spending but does not tie investments to expected loss, making it unsuitable for the CFO's request for a financial metric based on cyber event impact.
- ✓
Calculate the annualized loss expectancy (ALE) for each initiative based on risk assessment data.
Why this is correct
ALE expresses risk in financial terms by multiplying the single loss expectancy by the annualized rate of occurrence, directly linking security spending to expected monetary loss. This allows the CISO to compare initiatives on a consistent financial basis and justify investments to the CFO using the same language as other business cases.
- ✗
Track the percentage of employees who completed security awareness training.
Why it's wrong here
Training completion is a compliance and cultural metric, not a financial one. It measures program reach but does not quantify potential loss from cyber events, so it cannot be used to justify investments in monetary terms as requested by the CFO.
- ✗
Report the number of security incidents detected per quarter.
Why it's wrong here
Incident counts are operational metrics that do not translate directly into financial impact. While they indicate activity, they fail to express potential loss or return on investment, so they do not satisfy the CFO's requirement for a financial metric tied to cyber events.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.