Courseiva

CISM Information Security Governance Practice Question

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

⚠ Common exam trap

CISM often tests the distinction between operational metrics (alert counts, patch age) and strategic/governance metrics (compliance %, MTTR, investment %) — candidates pick the most technical-sounding metrics instead of the ones a board can act on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch compliance percentage for critical systems

Option B (Patch compliance percentage for critical systems) is correct because it expresses vulnerability-management effectiveness as a single risk-oriented ratio the board can track over time, showing how much of the most important estate is protected rather than raw operational detail. Option C (Mean time to respond (MTTR) to incidents) is correct because it is a standard resilience KPI that quantifies how quickly the organization contains and recovers from incidents, which is a governance-level measure of response capability. Option E (Security investment as a percentage of IT budget) is correct because it frames security spending in business and financial terms, letting the board judge whether resourcing is proportionate to risk appetite and peer benchmarks. Option A is not appropriate because average patch age in days is a granular operational/tactical metric better suited to security operations or IT management than the board. Option D is not appropriate because the raw daily count of intrusion detection alerts is a high-volume operational metric that reflects sensor tuning and noise, not strategic security posture or business risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Average age of security patches in days

    Why it's wrong here

    Patch age is an operational vulnerability-management metric tracking remediation tempo, too granular for board-level risk reporting. It tempts because it is quantifiable and security-relevant, yet boards need strategic exposure and risk-trend measures rather than day-to-day patching statistics.

  • ✓

    Patch compliance percentage for critical systems

    Why this is correct

    Patch compliance percentage for critical systems translates operational vulnerability exposure into a governance-level risk indicator the board can track. It satisfies the stem's board-reporting constraint by measuring control effectiveness against a defined baseline, rather than raw technical counts. Directors can assess whether remediation keeps pace with threats, linking directly to risk appetite and oversight accountability.

  • ✓

    Mean time to respond (MTTR) to incidents

    Why this is correct

    Mean time to respond measures how quickly the security team contains incidents, giving the board a direct view of operational resilience. It satisfies the stem's board-level constraint by expressing response capability in business-relevant terms, unlike technical metrics such as patch latency or vulnerability counts, which lack strategic meaning for directors.

  • ✗

    Number of intrusion detection alerts per day

    Why it's wrong here

    Raw intrusion-detection alert counts are operational telemetry that fluctuate daily and lack business context, so they do not inform board-level risk decisions. They are tempting because they are easy to collect, but that scenario calls for strategic metrics such as risk posture, incident impact and control effectiveness.

  • ✓

    Security investment as a percentage of IT budget

    Why this is correct

    Security investment as a percentage of IT budget expresses spend in financial terms the board already governs. It satisfies the board-level constraint by translating security posture into budgetary language, enabling comparison against peers and supporting resourcing decisions.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.