Courseiva

CISM Information Security Governance Practice Question

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

⚠ Common exam trap

CISM often tests the difference between culture metrics (behavioral) and program metrics (budget, policy counts) — candidates pick budget or policy counts because they are easy to quantify, but they don't measure culture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing simulation click rate

Phishing simulation click rate (A) is a direct behavioral metric that reveals how susceptible employees are to real-world social-engineering attacks, making it a strong indicator of security awareness culture. Training completion rate (B) measures how consistently the workforce engages with required security education, which reflects the organization's commitment to building security knowledge. Percentage of incidents due to human error (E) quantifies how often employee mistakes contribute to breaches, directly exposing cultural weaknesses in day-to-day security behavior. Security budget as percentage of IT budget (C) is a financial resource metric, not a measure of employee attitudes or behavior, so it does not reflect security culture. Number of security policies published (D) is a documentation output metric and says nothing about whether employees understand or follow those policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Phishing simulation click rate

    Why this is correct

    Phishing simulation click rate reveals how employees actually behave when targeted, exposing the gap between awareness and practice. It satisfies the stem by measuring culture through observed behaviour rather than policy existence or training attendance.

  • ✓

    Training completion rate

    Why this is correct

    Training completion rate shows how much of the workforce has engaged with awareness content, indicating cultural reach and participation. It satisfies the stem as a quantitative culture metric, though it measures exposure rather than demonstrated behaviour.

  • ✗

    Security budget as percentage of IT budget

    Why it's wrong here

    Budget share measures resourcing, not employee beliefs or behaviour, so it does not reflect security culture. It is tempting because budget indicates management commitment, but culture metrics must capture attitudes, awareness, and reported behaviours rather than spending ratios.

  • ✗

    Number of security policies published

    Why it's wrong here

    Counting published policies measures documentation output, not whether staff understand or follow them, so it does not gauge culture. It is tempting because policies signal intent, but culture requires metrics on awareness, behaviour, and reporting rather than document volume.

  • ✓

    Percentage of incidents due to human error

    Why this is correct

    Human-error incident percentage directly measures employee behaviour and awareness, revealing whether staff follow secure practise or bypass controls. Unlike policy counts or training completion, it reflects actual culture outcomes, making it a valid indicator of the organisation's security mindset.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.