mediumMultiple Choice
CISM Practice Question: An information security manager is preparing a…
An information security manager is preparing a report for the board on the state of information security governance. Which of the following elements is most important to include in the report?
⚠ Common exam trap
Test-takers frequently confuse operational reporting (incident logs, tool lists) with governance reporting, which demands high-level, risk-focused metrics like KRIs that support strategic oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Key risk indicators (KRIs) related to the organization's critical assets.
Key risk indicators (KRIs) provide a forward-looking, quantifiable measure of risk exposure tied directly to critical assets, which is essential for the board to understand the effectiveness of governance and risk management. Unlike operational or tactical data, KRIs enable informed strategic decisions about risk appetite and resource allocation, aligning with the CISM focus on governance over management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The percentage of the security budget spent on different projects.
Why it's wrong here
Budget allocation percentages show resourcing, not whether security is governed effectively or aligned with business objectives. It is tempting because spend is easily quantified and boards scrutinise budgets, but this belongs in financial reporting; governance reporting addresses risk posture, direction and accountability.
- ✓
Key risk indicators (KRIs) related to the organization's critical assets.
Why this is correct
KRIs give the board forward-looking, quantified insight into exposures affecting critical assets, linking security posture to business risk. This supports informed risk-based decisions and oversight, which is the board's governance responsibility rather than operational detail.
- ✗
A log of all recent security incidents and their root causes.
Why it's wrong here
An incident log with root causes is operational detail; the board needs aggregated governance information such as risk trends and programme effectiveness. It is tempting because incidents demonstrate security activity, and such logs suit management or operational reviews rather than governance reporting.
- ✗
A detailed list of all security tools and their functionalities.
Why it's wrong here
Tool inventories and feature lists describe operational detail, not governance posture, so the board gains no view of risk, alignment or performance. It is tempting because tooling underpins security, and such detail belongs in technical or management reporting rather than a governance report to the board.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.