CISM Information Security Programme Practice Question
A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)
⚠ Common exam trap
The trap here is equating ease of data collection or technical detail with metric effectiveness, but alignment and actionability are what make metrics valuable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are aligned with business objectives.
Effective security metrics are aligned with business objectives and are actionable, leading to decisions. These characteristics ensure that metrics are relevant to executive management and support strategic oversight. Other traits, such as ease of collection or technical jargon, do not guarantee effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They remain static over time.
Why it's wrong here
Metrics should evolve as the organization's risk landscape, business objectives, and security program mature. Static metrics may become irrelevant or fail to capture new risks. Regular review and adjustment ensure that metrics continue to provide value and reflect current priorities.
- ✓
They are aligned with business objectives.
Why this is correct
Metrics aligned with business objectives ensure that security efforts support organizational goals and are relevant to executive management. They provide meaningful insights into how security contributes to business success, enabling informed decision-making. This alignment is a key characteristic of effective metrics.
- ✓
They are actionable and lead to decisions.
Why this is correct
Effective metrics must be actionable, meaning they provide information that can guide decisions and improvements. If a metric does not lead to action, it is merely data. Actionability ensures that metrics support management and oversight, which is essential for executive reporting.
- ✗
They are based on data that is easy to collect.
Why it's wrong here
Ease of collection is a practical consideration but not a primary characteristic of effectiveness. Metrics should be meaningful and actionable, even if collection requires effort. Prioritizing ease over relevance can lead to metrics that do not inform decision-making or reflect true security posture.
- ✗
They are expressed in technical jargon.
Why it's wrong here
Technical jargon can confuse executives and obscure meaning. Effective metrics should be communicated in business terms that are easily understood by non-technical stakeholders. Clarity is essential for executive management to grasp the implications and make informed decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.