Courseiva

CISM Information Security Programme Practice Question

An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?

⚠ Common exam trap

The trap here is equating KRIs with performance measurement, when their defining purpose is predictive risk warning rather than process efficiency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A KRI provides early warning of increasing risk exposure.

A key risk indicator is forward-looking, providing early warning of increasing risk exposure so leadership can act before incidents occur. A key performance indicator measures how well processes meet targets. The CISO should use KRIs to anticipate risk and KPIs to assess operational effectiveness, ensuring the metrics program supports proactive risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A KRI is always a lagging indicator of past incidents.

    Why it's wrong here

    KRIs are typically leading indicators designed to forecast potential issues. Lagging indicators, such as number of breaches, report what already happened. Labeling a KRI as always lagging inverts its purpose and removes its predictive value, which is precisely what distinguishes it from historical performance metrics.

  • ✗

    A KRI is reported only to the board, while a KPI is reported to management.

    Why it's wrong here

    Audience does not define a KRI. Both KRIs and KPIs can be reported at multiple levels depending on materiality. The distinction lies in purpose: KRIs indicate risk exposure, KPIs indicate performance. Assigning metrics by audience alone can misclassify them and dilute the risk signal the board needs.

  • ✗

    A KRI measures how well security processes are performing against targets.

    Why it's wrong here

    Measuring process performance against targets describes a KPI, not a KRI. KPIs track efficiency and effectiveness of controls and operations. A KRI instead focuses on the likelihood or potential impact of future adverse events. Confusing the two leads to dashboards that report operational health without warning of emerging risk exposure.

  • ✓

    A KRI provides early warning of increasing risk exposure.

    Why this is correct

    A key risk indicator is a forward-looking metric that signals rising risk before it materializes into incidents. It helps the organization anticipate and mitigate threats. Unlike a KPI, which measures performance against objectives, a KRI tracks conditions that could lead to loss, such as increasing vulnerability counts or growing third-party exposure.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.