Courseiva
easyMultiple Choice

CISM Practice Question: Is the best indicator that an organization has…

Which of the following is the best indicator that an organization has effective information security governance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security metrics are reviewed by the board quarterly

(ISO 27001 certification) indicates compliance, not necessarily governance performance. Option B (security budget increased) does not guarantee effectiveness. Option C (low number of incidents) could be due to luck. Option D (board review of metrics) demonstrates governance oversight and strategic alignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Achievement of ISO 27001 certification

    Why it's wrong here

    Certification evidences point-in-time conformity with ISO 27001 controls, not ongoing governance effectiveness; it can be maintained while risk decisions bypass leadership. It is tempting because certification is a recognised assurance milestone, and would be the right answer if the question asked how to demonstrate baseline control compliance to external parties.

  • ✗

    The security budget has increased year over year

    Why it's wrong here

    A rising budget shows spending growth, not that security investment aligns with business objectives and risk tolerance, which is what governance delivers. It is tempting because sustained funding signals executive commitment, and would be the correct indicator if the question asked about resourcing trends rather than governance effectiveness.

  • ✗

    Low number of security incidents

    Why it's wrong here

    Incident counts reflect detection, reporting and tolerance thresholds, not governance effectiveness; mature programmes often report more incidents. It is tempting because fewer incidents appears to signal strong control, which suits measuring operational stability rather than evaluating governance structures and accountability.

  • ✓

    Security metrics are reviewed by the board quarterly

    Why this is correct

    Board-level quarterly review of security metrics demonstrates that governance is actively directed and monitored at the highest level, not delegated and forgotten. This satisfies the stem's effectiveness indicator by showing accountability, oversight, and alignment between security performance and enterprise objectives.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.