Courseiva
easyMultiple ChoiceObjective-mapped

CISM Practice Question: Is the best indicator that an organization has…

Which of the following is the best indicator that an organization has effective information security governance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security metrics are reviewed by the board quarterly

(ISO 27001 certification) indicates compliance, not necessarily governance performance. Option B (security budget increased) does not guarantee effectiveness. Option C (low number of incidents) could be due to luck. Option D (board review of metrics) demonstrates governance oversight and strategic alignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Achievement of ISO 27001 certification

    Why it's wrong here

    Achievement of ISO 27001 certification indicates compliance with a standard, but does not measure the effectiveness of governance oversight.

  • The security budget has increased year over year

    Why it's wrong here

    An increasing security budget shows prioritization of security but does not demonstrate that governance processes are effective.

  • Low number of security incidents

    Why it's wrong here

    A low number of security incidents could be due to external factors, luck, or underreporting, not necessarily effective governance.

  • Security metrics are reviewed by the board quarterly

    Why this is correct

    Security metrics reviewed by the board ensure strategic alignment and accountability, which is the best indicator of effective governance.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.