easyMultiple Choice
CISM Practice Question: Is the best indicator that an organization has…
Which of the following is the best indicator that an organization has effective information security governance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security metrics are reviewed by the board quarterly
(ISO 27001 certification) indicates compliance, not necessarily governance performance. Option B (security budget increased) does not guarantee effectiveness. Option C (low number of incidents) could be due to luck. Option D (board review of metrics) demonstrates governance oversight and strategic alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Achievement of ISO 27001 certification
Why it's wrong here
Certification evidences point-in-time conformity with ISO 27001 controls, not ongoing governance effectiveness; it can be maintained while risk decisions bypass leadership. It is tempting because certification is a recognised assurance milestone, and would be the right answer if the question asked how to demonstrate baseline control compliance to external parties.
- ✗
The security budget has increased year over year
Why it's wrong here
A rising budget shows spending growth, not that security investment aligns with business objectives and risk tolerance, which is what governance delivers. It is tempting because sustained funding signals executive commitment, and would be the correct indicator if the question asked about resourcing trends rather than governance effectiveness.
- ✗
Low number of security incidents
Why it's wrong here
Incident counts reflect detection, reporting and tolerance thresholds, not governance effectiveness; mature programmes often report more incidents. It is tempting because fewer incidents appears to signal strong control, which suits measuring operational stability rather than evaluating governance structures and accountability.
- ✓
Security metrics are reviewed by the board quarterly
Why this is correct
Board-level quarterly review of security metrics demonstrates that governance is actively directed and monitored at the highest level, not delegated and forgotten. This satisfies the stem's effectiveness indicator by showing accountability, oversight, and alignment between security performance and enterprise objectives.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.