Courseiva
easyMultiple ChoiceObjective-mapped

Key Metrics for Information Security Governance Effectiveness

An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?

Quick Answer

The answer is the percentage of risk treatment plans that have been implemented as scheduled. This metric directly measures whether the governance body’s decisions are being translated into action, which is the core purpose of information security governance effectiveness. Unlike operational metrics such as mean time to detect, which track tactical response, or incident counts, which can fluctuate due to external threats, the implementation rate of risk treatment plans reflects the execution of strategic oversight and accountability. On the Certified Information Security Manager CISM exam, this question tests your ability to distinguish governance-level metrics from operational or financial ones—a common trap is confusing “effectiveness” with “efficiency” or “activity.” Remember the memory tip: “Governance governs action, not reaction”—so look for metrics that track whether planned risk treatments are actually completed, not how fast you detect or how much you spend.

⚠ Common exam trap

The CISM exam often tests the distinction between governance metrics (e.g., risk treatment implementation) and operational metrics (e.g., MTTD, incident counts), and the trap here is that candidates confuse operational efficiency with governance effectiveness, picking a metric that sounds security-relevant but does not measure process oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Percentage of risk treatment plans that have been implemented as scheduled.

The percentage of risk treatment plans implemented as scheduled directly measures whether the governance process is translating risk decisions into action. Effective governance ensures that risk owners execute agreed-upon treatments within defined timelines, reflecting accountability and process adherence. This metric aligns with the CISM governance principle that oversight should focus on outcomes of risk management activities, not just operational metrics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Total spending on security tools compared to the approved budget.

    Why it's wrong here

    Spending compliance does not indicate governance effectiveness.

  • Percentage of risk treatment plans that have been implemented as scheduled.

    Why this is correct

    This shows whether governance decisions on risk are being carried out.

  • Number of security incidents reported per quarter.

    Why it's wrong here

    Incident count is an outcome, not a measure of governance process health.

  • Mean time to detect (MTTD) for security incidents.

    Why it's wrong here

    Mean time to detect (MTTD) measures the speed of incident detection, not the effectiveness of governance processes. Governance functioning is indicated by metrics such as board-level security reporting frequency or policy compliance rates, which assess oversight and accountability. MTTD is tempting because it is a common operational metric for security operations centre performance, and would be correct when evaluating the efficiency of the detection function rather than governance.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?

hard
  • A.Number of security alerts triaged per day.
  • B.Reduction in average cost per security incident over the past year.
  • C.Time to patch critical vulnerabilities.
  • D.Percentage of systems with endpoint protection installed.

Why B: The reduction in average cost per security incident directly translates security program outcomes into financial terms that resonate with the board. This metric demonstrates the program's effectiveness by quantifying the monetary value of improved prevention, detection, and response capabilities, aligning with the CISM focus on governance and business alignment.

Variation 2. Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)

hard
  • A.Security risk appetite is defined and reported to the board
  • B.Mean time to patch critical vulnerabilities is under 48 hours
  • C.Security performance metrics are linked to business outcomes
  • D.Security strategy is reviewed and updated annually based on business changes
  • E.Number of security incidents decreased by 20% year-over-year

Why A: Defining and reporting security risk appetite to the board is a foundational governance activity that ensures executive oversight and alignment of risk tolerance with business strategy. In a mature governance process, the board must formally approve and periodically review the risk appetite statement, which directly influences resource allocation and control prioritization. This aligns with the ISACA CISM framework, which emphasizes that governance requires board-level engagement with risk appetite as a key performance indicator.

Variation 3. Which TWO of the following are key indicators that an organization's information security governance is effective?

medium
  • A.Low variance between the approved security budget and actual spending.
  • B.The number of security policies that have been published.
  • C.High percentage of risk treatment plans implemented on time.
  • D.Regular reporting of security performance metrics to the board.
  • E.High completion rate for security awareness training.

Why C: Timely implementation of risk treatment plans directly demonstrates that the organization is actively managing identified risks according to its risk appetite and governance framework. Effective governance requires not just planning but execution; a high percentage of on-time plan completion indicates that risk owners are accountable and that the risk management process is operational, which is a core objective of information security governance.

Variation 4. Which TWO of the following are key indicators that an organization's information security governance is inadequate?

hard
  • A.Low budget for security awareness
  • B.Frequent changes to security policies without approval
  • C.High number of security incidents
  • D.Use of multiple antivirus solutions
  • E.Absence of a risk appetite statement

Why B: Frequent changes to security policies without approval (Option B) indicate a breakdown in governance because it shows that the policy lifecycle—creation, review, approval, and communication—is not being followed. Without a formal change control process, policies become inconsistent, unenforceable, and may conflict with regulatory requirements, directly undermining the governance framework's authority and accountability.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.