CISM Information Security Governance Practice Question
A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security investment vs. loss avoidance
Comparing security investment to potential loss avoidance quantifies ROI in business terms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security incidents
Why it's wrong here
Incident counts measure the existing threat landscape and detection volume, not the tool's contribution; a rising count could even indicate improved detection. It is tempting as a baseline security metric, but a business case needs risk reduction or cost avoidance, such as expected losses prevented, to demonstrate investment value.
- ✗
Percentage of budget spent on security
Why it's wrong here
Budget percentage is an input or efficiency measure, showing spend allocation rather than value delivered; spending more on security does not itself demonstrate benefit. It is tempting because it is easy to calculate, but a business case requires quantified risk reduction or avoided loss attributable to the tool.
- ✓
Security investment vs. loss avoidance
Why this is correct
Comparing the proposed spend against projected loss avoidance expresses security value in financial terms the business case requires. It satisfies the investment-justification constraint by demonstrating that the tool reduces expected loss exposure more than it costs.
- ✗
Time to implement the tool
Why it's wrong here
Implementation time measures delivery effort, not the security or financial benefit realised after deployment. It is tempting because project schedules are visible and easy to report, but a business case must show value through reduced risk exposure or cost avoidance, not how quickly the tool was rolled out.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.