easyMultiple Choice
Key Metrics for Information Security Governance Effectiveness
An information security manager is evaluating the effectiveness of the organization's security governance. Which of the following metrics would best indicate that governance processes are functioning properly?
Quick Answer
The answer is the percentage of risk treatment plans that have been implemented as scheduled. This metric directly measures whether the governance body’s decisions are being translated into action, which is the core purpose of information security governance effectiveness. Unlike operational metrics such as mean time to detect, which track tactical response, or incident counts, which can fluctuate due to external threats, the implementation rate of risk treatment plans reflects the execution of strategic oversight and accountability. On the Certified Information Security Manager CISM exam, this question tests your ability to distinguish governance-level metrics from operational or financial ones—a common trap is confusing “effectiveness” with “efficiency” or “activity.” Remember the memory tip: “Governance governs action, not reaction”—so look for metrics that track whether planned risk treatments are actually completed, not how fast you detect or how much you spend.
⚠ Common exam trap
The CISM exam often tests the distinction between governance metrics (e.g., risk treatment implementation) and operational metrics (e.g., MTTD, incident counts), and the trap here is that candidates confuse operational efficiency with governance effectiveness, picking a metric that sounds security-relevant but does not measure process oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of risk treatment plans that have been implemented as scheduled.
The percentage of risk treatment plans implemented as scheduled directly measures whether the governance process is translating risk decisions into action. Effective governance ensures that risk owners execute agreed-upon treatments within defined timelines, reflecting accountability and process adherence. This metric aligns with the CISM governance principle that oversight should focus on outcomes of risk management activities, not just operational metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Total spending on security tools compared to the approved budget.
Why it's wrong here
Budget adherence measures financial control, not whether governance processes direct and monitor security effectively. Governance effectiveness shows through policy compliance, risk treatment and decision-making outcomes. Spend tracking is tempting because it is easy to report, and it would suit a cost-management or budget-variance question rather than a governance-maturity one.
- ✓
Percentage of risk treatment plans that have been implemented as scheduled.
Why this is correct
Risk treatment plans are the operational output of governance decisions. Tracking the percentage implemented as scheduled measures whether agreed controls are actually delivered, demonstrating that governance direction translates into executed action rather than remaining documented intent.
- ✗
Number of security incidents reported per quarter.
Why it's wrong here
Incident counts measure operational security performance, not governance. A rising or falling tally reflects threat activity and detection capability, and governance can be sound while incidents still occur. It is tempting because incidents are visible and quantifiable, and the metric would fit a question about security operations effectiveness rather than governance functioning.
- ✗
Mean time to detect (MTTD) for security incidents.
Why it's wrong here
Mean time to detect (MTTD) measures the speed of incident detection, not the effectiveness of governance processes. Governance functioning is indicated by metrics such as board-level security reporting frequency or policy compliance rates, which assess oversight and accountability. MTTD is tempting because it is a common operational metric for security operations centre performance, and would be correct when evaluating the efficiency of the detection function rather than governance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?
hard- A.Number of security alerts triaged per day.
- ✓ B.Reduction in average cost per security incident over the past year.
- C.Time to patch critical vulnerabilities.
- D.Percentage of systems with endpoint protection installed.
Why B: The reduction in average cost per security incident directly translates security program outcomes into financial terms that resonate with the board. This metric demonstrates the program's effectiveness by quantifying the monetary value of improved prevention, detection, and response capabilities, aligning with the CISM focus on governance and business alignment.
Variation 2. Which THREE of the following are key indicators of a mature information security governance process? (Select exactly three.)
hard- ✓ A.Security risk appetite is defined and reported to the board
- B.Mean time to patch critical vulnerabilities is under 48 hours
- ✓ C.Security performance metrics are linked to business outcomes
- ✓ D.Security strategy is reviewed and updated annually based on business changes
- E.Number of security incidents decreased by 20% year-over-year
Why A: Option A is correct because a mature governance process requires the board to formally define and regularly receive reporting on the organization's security risk appetite, ensuring risk decisions align with strategic direction and accountability sits at the top. Option C is correct because mature governance ties security performance metrics to business outcomes (e.g., availability, revenue protection, customer trust), demonstrating that security is managed as a business enabler rather than a purely technical function. Option D is correct because governance maturity demands that the security strategy be reviewed and updated at least annually in response to business, regulatory, and threat landscape changes, keeping strategy aligned with organizational objectives. Option B is not a governance indicator but a tactical operational metric for vulnerability management, and Option E is a lagging outcome metric that reflects incident trends rather than the existence of governance structures, oversight, and strategic alignment.
Variation 3. Which TWO of the following are key indicators that an organization's information security governance is effective?
medium- A.Low variance between the approved security budget and actual spending.
- B.The number of security policies that have been published.
- ✓ C.High percentage of risk treatment plans implemented on time.
- ✓ D.Regular reporting of security performance metrics to the board.
- E.High completion rate for security awareness training.
Why C: Option C is correct because effective governance is measured by whether the organization actually executes on its risk decisions — a high percentage of risk treatment plans implemented on time demonstrates that identified risks are being managed and that accountability and oversight processes are functioning, not just documented. Option D is correct because regular reporting of security performance metrics to the board is a defining characteristic of governance: it shows executive/board-level oversight, ensures security is aligned with business objectives, and enables informed direction-setting and resource decisions. The unmarked options do not belong: A (low budget variance) reflects financial control/accounting accuracy rather than security governance effectiveness, B (number of published policies) is a volume/output metric that says nothing about whether policies are enforced or effective, and E (security awareness training completion) is an operational control metric that indicates training delivery, not governance effectiveness.
Variation 4. Which TWO of the following are key indicators that an organization's information security governance is inadequate?
hard- A.Low budget for security awareness
- ✓ B.Frequent changes to security policies without approval
- C.High number of security incidents
- D.Use of multiple antivirus solutions
- ✓ E.Absence of a risk appetite statement
Why B: Frequent changes to security policies without approval (Option B) indicate a breakdown in governance because it shows that the policy lifecycle—creation, review, approval, and communication—is not being followed. Without a formal change control process, policies become inconsistent, unenforceable, and may conflict with regulatory requirements, directly undermining the governance framework's authority and accountability.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.