CISM Information Security Governance Practice Question
An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?
⚠ Common exam trap
CISM often tests the distinction between operational metrics (alert counts, patch age) and strategic/governance metrics (compliance %, MTTR, investment %) — candidates pick the most technical-sounding metrics instead of the ones a board can act on.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch compliance percentage for critical systems
Option B (Patch compliance percentage for critical systems) is correct because it expresses vulnerability-management effectiveness as a single risk-oriented ratio the board can track over time, showing how much of the most important estate is protected rather than raw operational detail. Option C (Mean time to respond (MTTR) to incidents) is correct because it is a standard resilience KPI that quantifies how quickly the organization contains and recovers from incidents, which is a governance-level measure of response capability. Option E (Security investment as a percentage of IT budget) is correct because it frames security spending in business and financial terms, letting the board judge whether resourcing is proportionate to risk appetite and peer benchmarks. Option A is not appropriate because average patch age in days is a granular operational/tactical metric better suited to security operations or IT management than the board. Option D is not appropriate because the raw daily count of intrusion detection alerts is a high-volume operational metric that reflects sensor tuning and noise, not strategic security posture or business risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Average age of security patches in days
Why it's wrong here
Patch age is an operational vulnerability-management metric tracking remediation tempo, too granular for board-level risk reporting. It tempts because it is quantifiable and security-relevant, yet boards need strategic exposure and risk-trend measures rather than day-to-day patching statistics.
- ✓
Patch compliance percentage for critical systems
Why this is correct
Patch compliance percentage for critical systems translates operational vulnerability exposure into a governance-level risk indicator the board can track. It satisfies the stem's board-reporting constraint by measuring control effectiveness against a defined baseline, rather than raw technical counts. Directors can assess whether remediation keeps pace with threats, linking directly to risk appetite and oversight accountability.
- ✓
Mean time to respond (MTTR) to incidents
Why this is correct
Mean time to respond measures how quickly the security team contains incidents, giving the board a direct view of operational resilience. It satisfies the stem's board-level constraint by expressing response capability in business-relevant terms, unlike technical metrics such as patch latency or vulnerability counts, which lack strategic meaning for directors.
- ✗
Number of intrusion detection alerts per day
Why it's wrong here
Raw intrusion-detection alert counts are operational telemetry that fluctuate daily and lack business context, so they do not inform board-level risk decisions. They are tempting because they are easy to collect, but that scenario calls for strategic metrics such as risk posture, incident impact and control effectiveness.
- ✓
Security investment as a percentage of IT budget
Why this is correct
Security investment as a percentage of IT budget expresses spend in financial terms the board already governs. It satisfies the board-level constraint by translating security posture into budgetary language, enabling comparison against peers and supporting resourcing decisions.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.