Courseiva

CISM Board-relevant security metric Practice Question

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

⚠ Common exam trap

Many candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of systems with critical vulnerabilities

The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security incidents reported

    Why it's wrong here

    Raw incident counts fluctuate with detection capability and reporting culture, so they do not convey risk exposure or business impact to the board. They are tempting because the data is readily available from the service desk, and volume trends are useful for operational security monitoring.

  • ✓

    Percentage of systems with critical vulnerabilities

    Why this is correct

    Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.

  • ✗

    Average patch deployment time

    Why it's wrong here

    Average patch deployment time is an operational process metric; it does not express residual risk, financial impact or alignment with business objectives that the board needs. It is tempting because it is quantifiable and readily available from patch management tooling, making it a valid measure for IT operations oversight.

  • ✗

    Number of security awareness training completions

    Why it's wrong here

    Training completion counts measure activity, not risk reduction or control effectiveness, so they give the board no view of exposure. They are tempting because completion rates are easy to collect and track, and they suit operational reporting to security management rather than strategic governance reporting.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.

✓Percentage of systems with critical vulnerabilitiesCorrect answer▾

Why this is correct

Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.

✗Number of security incidents reportedWrong answer — click to see why▾

Why this is wrong here

Lagging indicator; board prefers leading indicators of risk.

✗Average patch deployment timeWrong answer — click to see why▾

Why this is wrong here

Operational detail; not strategic.

✗Number of security awareness training completionsWrong answer — click to see why▾

Why this is wrong here

Activity metric, not outcome.

Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.