CISM Information Security Program Practice Question
A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?
⚠ Common exam trap
The trap is selecting activity or spend metrics (patches, policies, budget) that are easy to count but do not demonstrate value — CISM consistently favors outcome-based metrics tied to risk reduction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to detect incidents
Mean time to detect (MTTD) incidents directly measures how quickly the security program identifies threats, which is a core outcome executives care about — reduced exposure window and improved resilience. It demonstrates program effectiveness in a business-relevant way rather than just activity or spend.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Percentage of budget spent on security
Why it's wrong here
Budget percentage measures investment, not outcome, so it cannot show whether security objectives are met. It tempts because spend is easy to report; executives need risk reduction and control effectiveness, which this figure does not convey.
- ✗
Number of security patches applied
Why it's wrong here
Patch counts measure activity volume, not risk reduction or programme value. It tempts because the number is simple to collect; executives need metrics tied to reduced exposure or compliance, which raw patch totals do not demonstrate.
- ✗
Number of security policies created
Why it's wrong here
Counting policies created measures activity volume, not risk reduction or programme value. Policy counts suit a compliance-completeness or documentation audit, whereas executives need metrics tied to risk exposure, such as reduced incidents, faster remediation or control coverage against agreed tolerances.
- ✓
Mean time to detect incidents
Why this is correct
Mean time to detect incidents quantifies how quickly the security function identifies threats, a capability executives directly link to reduced breach impact and programme effectiveness. It demonstrates operational value more concretely than activity counts or compliance percentages, satisfying the requirement to show programme worth.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.