Courseiva

CISM Information Security Program Practice Question

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

⚠ Common exam trap

The trap is selecting activity or spend metrics (patches, policies, budget) that are easy to count but do not demonstrate value — CISM consistently favors outcome-based metrics tied to risk reduction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to detect incidents

Mean time to detect (MTTD) incidents directly measures how quickly the security program identifies threats, which is a core outcome executives care about — reduced exposure window and improved resilience. It demonstrates program effectiveness in a business-relevant way rather than just activity or spend.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Percentage of budget spent on security

    Why it's wrong here

    Budget percentage measures investment, not outcome, so it cannot show whether security objectives are met. It tempts because spend is easy to report; executives need risk reduction and control effectiveness, which this figure does not convey.

  • ✗

    Number of security patches applied

    Why it's wrong here

    Patch counts measure activity volume, not risk reduction or programme value. It tempts because the number is simple to collect; executives need metrics tied to reduced exposure or compliance, which raw patch totals do not demonstrate.

  • ✗

    Number of security policies created

    Why it's wrong here

    Counting policies created measures activity volume, not risk reduction or programme value. Policy counts suit a compliance-completeness or documentation audit, whereas executives need metrics tied to risk exposure, such as reduced incidents, faster remediation or control coverage against agreed tolerances.

  • ✓

    Mean time to detect incidents

    Why this is correct

    Mean time to detect incidents quantifies how quickly the security function identifies threats, a capability executives directly link to reduced breach impact and programme effectiveness. It demonstrates operational value more concretely than activity counts or compliance percentages, satisfying the requirement to show programme worth.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.