CISM Information Security Governance Practice Question
A security manager is developing key performance indicators (KPIs) for the information security program. Which of the following is the MOST important characteristic of an effective KPI?
⚠ Common exam trap
The trap here is focusing on operational ease or external comparisons instead of strategic alignment, which is the cornerstone of effective security metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is aligned with business objectives.
The most critical characteristic of a KPI is alignment with business objectives, as this ensures that security performance is measured in terms of its contribution to organizational goals. This alignment helps justify security investments and demonstrates value to stakeholders. Other characteristics like measurability and benchmarking are secondary to strategic relevance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is easy to measure and report.
Why it's wrong here
Ease of measurement is desirable but not the most important characteristic. A KPI must first be relevant to business objectives and security goals. If a KPI is easy to measure but does not reflect the program's effectiveness, it provides little value. The focus should be on meaningful metrics that drive decisions.
- ✗
It is based on industry benchmarks.
Why it's wrong here
Industry benchmarks can provide context, but they are not the most important characteristic. Benchmarks may not reflect the organization's specific risk profile, business model, or strategic priorities. KPIs should be tailored to the organization's unique objectives and risk appetite.
- ✗
It is reviewed annually by the board.
Why it's wrong here
Board review is part of governance, but the frequency and audience do not define an effective KPI. A KPI should be aligned with business objectives and measurable. Annual review alone does not ensure relevance or usefulness for decision-making.
- ✓
It is aligned with business objectives.
Why this is correct
Effective KPIs must align with business objectives to demonstrate how security contributes to organizational success. This alignment ensures that security efforts support strategic goals, such as protecting revenue, maintaining customer trust, and enabling safe innovation. Without alignment, KPIs may measure activity rather than value, leading to misdirected resources.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.