CISM Metric for program effectiveness Practice Question
After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?
⚠ Common exam trap
CISM often tests the difference between activity-based metrics (e.g., training completion) and outcome-based metrics (e.g., incident containment); candidates may choose activity metrics because they are easier to measure, but effectiveness requires outcome measures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of security incidents detected and contained within defined SLAs
The most useful metric to demonstrate the effectiveness of an information security program is the number of security incidents detected and contained within defined SLAs. This metric directly measures the program's ability to detect and respond to incidents in a timely manner, which is a key indicator of operational effectiveness. It shows how well the program is performing in real-world scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Percentage of employees who completed security awareness training
Why it's wrong here
Training completion counts attendance, not reduced risk behaviour or incident outcomes, so it cannot evidence programme effectiveness. It is useful for tracking awareness campaign reach. Demonstrating effectiveness over a year requires metrics tied to incident frequency, response times or control failures.
- ✓
Number of security incidents detected and contained within defined SLAs
Why this is correct
Tracking incidents detected and contained within defined SLAs demonstrates the programme's operational effectiveness, showing both detection capability and response maturity over the year. This metric directly evidences whether controls and processes function as intended, which is what the board needs to assess programme performance.
- ✗
Total cost of security investments compared to industry benchmarks
Why it's wrong here
Spend against benchmarks measures investment, not whether controls reduced risk or incident impact, so it cannot evidence programme effectiveness. It is tempting because budgeting comparisons suit board-level reporting, and would be the right metric when justifying security funding or benchmarking spend against peers.
- ✗
Number of vulnerabilities identified in the latest penetration test
Why it's wrong here
A single penetration test's vulnerability count is a point-in-time technical snapshot, not a year-long measure of programme performance or risk reduction. It is tempting because penetration testing genuinely evidences control weaknesses, and would be correct when validating a specific system's defences before go-live.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Number of security incidents detected and contained within defined SLAsCorrect answer▾
Why this is correct
Tracking incidents detected and contained within defined SLAs demonstrates the programme's operational effectiveness, showing both detection capability and response maturity over the year. This metric directly evidences whether controls and processes function as intended, which is what the board needs to assess programme performance.
✗Percentage of employees who completed security awareness trainingWrong answer — click to see why▾
Why this is wrong here
Training completion is a leading indicator but does not measure program effectiveness in handling incidents.
✗Total cost of security investments compared to industry benchmarksWrong answer — click to see why▾
Why this is wrong here
Cost comparison does not indicate how well the program performed.
✗Number of vulnerabilities identified in the latest penetration testWrong answer — click to see why▾
Why this is wrong here
Vulnerability counts are point-in-time and not a comprehensive measure of program effectiveness.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.