CISM Board-relevant security metric Practice Question
An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?
⚠ Common exam trap
Many candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of systems with critical vulnerabilities
The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security incidents reported
Why it's wrong here
Raw incident counts fluctuate with detection capability and reporting culture, so they do not convey risk exposure or business impact to the board. They are tempting because the data is readily available from the service desk, and volume trends are useful for operational security monitoring.
- ✓
Percentage of systems with critical vulnerabilities
Why this is correct
Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.
- ✗
Average patch deployment time
Why it's wrong here
Average patch deployment time is an operational process metric; it does not express residual risk, financial impact or alignment with business objectives that the board needs. It is tempting because it is quantifiable and readily available from patch management tooling, making it a valid measure for IT operations oversight.
- ✗
Number of security awareness training completions
Why it's wrong here
Training completion counts measure activity, not risk reduction or control effectiveness, so they give the board no view of exposure. They are tempting because completion rates are easy to collect and track, and they suit operational reporting to security management rather than strategic governance reporting.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Percentage of systems with critical vulnerabilitiesCorrect answer▾
Why this is correct
Board-level reporting demands a risk-oriented, aggregated view rather than operational detail. The percentage of systems carrying critical vulnerabilities translates technical exposure into a governance-relevant trend, letting directors judge whether remediation is keeping pace with threats and where to direct investment.
✗Number of security incidents reportedWrong answer — click to see why▾
Why this is wrong here
Lagging indicator; board prefers leading indicators of risk.
✗Average patch deployment timeWrong answer — click to see why▾
Why this is wrong here
Operational detail; not strategic.
✗Number of security awareness training completionsWrong answer — click to see why▾
Why this is wrong here
Activity metric, not outcome.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.