hardMultiple ChoiceObjective-mapped
CISM Practice Question: A financial services firm has a mature…
A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?
⚠ Common exam trap
Watch out — candidates often choose a technical or operational metric (like time to patch or alert volume) because it seems directly measurable, but the CISM exam emphasizes that the board cares about business impact and financial outcomes, not technical details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in average cost per security incident over the past year.
The reduction in average cost per security incident directly translates security program outcomes into financial terms that resonate with the board. This metric demonstrates the program's effectiveness by quantifying the monetary value of improved prevention, detection, and response capabilities, aligning with the CISM focus on governance and business alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security alerts triaged per day.
Why it's wrong here
Operational metric, not a business value indicator.
- ✓
Reduction in average cost per security incident over the past year.
Why this is correct
Directly ties security program effectiveness to financial impact.
- ✗
Time to patch critical vulnerabilities.
Why it's wrong here
Technical metric, not directly showing business value.
- ✗
Percentage of systems with endpoint protection installed.
Why it's wrong here
Does not reflect business value or risk reduction.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.