CISM Information Security Governance Practice Question
A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?
⚠ Common exam trap
CISM often tests the difference between culture metrics (behavioral) and program metrics (budget, policy counts) — candidates pick budget or policy counts because they are easy to quantify, but they don't measure culture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing simulation click rate
Phishing simulation click rate (A) is a direct behavioral metric that reveals how susceptible employees are to real-world social-engineering attacks, making it a strong indicator of security awareness culture. Training completion rate (B) measures how consistently the workforce engages with required security education, which reflects the organization's commitment to building security knowledge. Percentage of incidents due to human error (E) quantifies how often employee mistakes contribute to breaches, directly exposing cultural weaknesses in day-to-day security behavior. Security budget as percentage of IT budget (C) is a financial resource metric, not a measure of employee attitudes or behavior, so it does not reflect security culture. Number of security policies published (D) is a documentation output metric and says nothing about whether employees understand or follow those policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing simulation click rate
Why this is correct
Phishing simulation click rate reveals how employees actually behave when targeted, exposing the gap between awareness and practice. It satisfies the stem by measuring culture through observed behaviour rather than policy existence or training attendance.
- ✓
Training completion rate
Why this is correct
Training completion rate shows how much of the workforce has engaged with awareness content, indicating cultural reach and participation. It satisfies the stem as a quantitative culture metric, though it measures exposure rather than demonstrated behaviour.
- ✗
Security budget as percentage of IT budget
Why it's wrong here
Budget share measures resourcing, not employee beliefs or behaviour, so it does not reflect security culture. It is tempting because budget indicates management commitment, but culture metrics must capture attitudes, awareness, and reported behaviours rather than spending ratios.
- ✗
Number of security policies published
Why it's wrong here
Counting published policies measures documentation output, not whether staff understand or follow them, so it does not gauge culture. It is tempting because policies signal intent, but culture requires metrics on awareness, behaviour, and reporting rather than document volume.
- ✓
Percentage of incidents due to human error
Why this is correct
Human-error incident percentage directly measures employee behaviour and awareness, revealing whether staff follow secure practise or bypass controls. Unlike policy counts or training completion, it reflects actual culture outcomes, making it a valid indicator of the organisation's security mindset.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.