hardMultiple Choice
CISM Practice Question: A financial services firm has a mature…
A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?
⚠ Common exam trap
Watch out — candidates often choose a technical or operational metric (like time to patch or alert volume) because it seems directly measurable, but the CISM exam emphasizes that the board cares about business impact and financial outcomes, not technical details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in average cost per security incident over the past year.
The reduction in average cost per security incident directly translates security program outcomes into financial terms that resonate with the board. This metric demonstrates the program's effectiveness by quantifying the monetary value of improved prevention, detection, and response capabilities, aligning with the CISM focus on governance and business alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security alerts triaged per day.
Why it's wrong here
Alert triage volume measures SOC workload, not risk reduction or business value, and can rise as detection worsens. It is tempting because it demonstrates analyst throughput, and would be the right metric for capacity planning or staffing a security operations centre.
- ✓
Reduction in average cost per security incident over the past year.
Why this is correct
Expressing effectiveness as reduced average cost per incident translates security outcomes into financial terms the board already tracks, directly satisfying the stem's demand for business-language value demonstration rather than technical metrics such as patch latency or vulnerability counts.
- ✗
Time to patch critical vulnerabilities.
Why it's wrong here
Patch latency measures operational remediation speed, not financial exposure reduction, so the board cannot link it to loss avoidance. It is tempting because vulnerability management programmes track it as a core SLA, and it would suit an operational security review or auditor evidence request.
- ✗
Percentage of systems with endpoint protection installed.
Why it's wrong here
Endpoint protection coverage is a control deployment measure, not an outcome showing reduced business risk. It is tempting because it evidences programme maturity, and would be correct when reporting compliance against a baseline control requirement to an auditor.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.