Internal Processes Perspective: Mean Time to Detect and Respond
An organization has implemented a balanced scorecard to measure the effectiveness of its information security program. Which of the following metrics would be MOST appropriate for the 'internal processes' perspective?
Quick Answer
The answer is mean time to detect and respond to incidents. This metric is the most appropriate for the internal processes perspective because it directly measures the efficiency and effectiveness of the security program’s operational workflows, specifically the incident response lifecycle. In a balanced scorecard, the internal processes perspective evaluates how well core activities—like threat detection and containment—are performed, and mean time to detect (MTTD) and mean time to respond (MTTR) are the definitive quantitative gauges of that performance. On the Certified Information Security Manager CISM exam, this question tests your ability to map operational metrics to the correct balanced scorecard dimension, often tripping candidates who confuse internal processes with customer or financial perspectives. A common trap is selecting a metric like “number of security incidents” which measures volume, not process efficiency. Remember the memory tip: “Processes are about the pipeline, not the product”—internal processes focus on how fast you move through the detection-to-response pipeline, not on the final outcome.
⚠ Common exam trap
Candidates often confuse the 'internal processes' perspective with compliance or training metrics, mistakenly selecting A or C because they seem operational, but the balanced scorecard framework specifically ties 'internal processes' to the efficiency of core security workflows like incident response, not static compliance or awareness rates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to detect and respond to incidents
The 'internal processes' perspective of a balanced scorecard focuses on the efficiency and effectiveness of the operational workflows that deliver the security program. Mean time to detect (MTTD) and mean time to respond (MTTR) directly measure the performance of the incident response process, which is a core internal process. This metric reflects how quickly the organization can identify and contain threats, making it the most appropriate choice for this perspective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Percentage of systems compliant with baseline
Why it's wrong here
Compliance rate is more aligned with the governance or regulatory perspective, not internal processes.
- ✗
Percentage of users who completed security awareness training
Why it's wrong here
This is a learning and growth metric, not internal processes.
- ✗
Number of security incidents reported to management
Why it's wrong here
This is more of an output metric, not specifically internal process efficiency.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Mean time to detect and respond to incidentsCorrect answer▾
✗Percentage of systems compliant with baselineWrong answer — click to see why▾
Why this is wrong here
Compliance rate is more aligned with the governance or regulatory perspective, not internal processes.
✗Percentage of users who completed security awareness trainingWrong answer — click to see why▾
Why this is wrong here
This is a learning and growth metric, not internal processes.
✗Number of security incidents reported to managementWrong answer — click to see why▾
Why this is wrong here
This is more of an output metric, not specifically internal process efficiency.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?
hard- A.Cost of security incidents as a percentage of revenue
- ✓ B.Percentage of security incidents detected within defined SLAs
- C.Number of security training hours per employee
- D.Customer satisfaction survey scores on data protection
Why B: The 'Internal Processes' perspective of a balanced scorecard focuses on the efficiency and effectiveness of internal operational processes. The percentage of security incidents detected within defined SLAs directly measures the performance of the security monitoring and incident response processes, which are core internal processes in a COBIT-based information security program.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.