Courseiva
mediumMultiple Select

CISM Practice Question: Which TWO of the following are key indicators…

Which TWO of the following are key indicators that an organization's information security governance is effective?

⚠ Common exam trap

Test-takers frequently confuse operational metrics (like training completion or budget adherence) with governance effectiveness, which requires evidence of strategic oversight, risk management execution, and board-level accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High percentage of risk treatment plans implemented on time.

Option C is correct because effective governance is measured by whether the organization actually executes on its risk decisions — a high percentage of risk treatment plans implemented on time demonstrates that identified risks are being managed and that accountability and oversight processes are functioning, not just documented. Option D is correct because regular reporting of security performance metrics to the board is a defining characteristic of governance: it shows executive/board-level oversight, ensures security is aligned with business objectives, and enables informed direction-setting and resource decisions. The unmarked options do not belong: A (low budget variance) reflects financial control/accounting accuracy rather than security governance effectiveness, B (number of published policies) is a volume/output metric that says nothing about whether policies are enforced or effective, and E (security awareness training completion) is an operational control metric that indicates training delivery, not governance effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Low variance between the approved security budget and actual spending.

    Why it's wrong here

    Budget-to-actual variance measures financial forecasting accuracy, not whether security spending delivers governed outcomes or aligns with risk appetite. It tempts because budget adherence is a genuine governance concern, and low variance would be the right indicator when assessing financial control over the security programme.

  • ✗

    The number of security policies that have been published.

    Why it's wrong here

    Counting published policies measures documentation output, not whether those policies are enforced, reviewed or reduce risk. It tempts because policy existence is a common audit artefact, and the count would be the right metric when demonstrating baseline documentation coverage during an initial maturity assessment.

  • ✓

    High percentage of risk treatment plans implemented on time.

    Why this is correct

    Timely completion of risk treatment plans demonstrates that governance decisions translate into executed remediation, not just documented intent. It measures whether identified risks are actually addressed within agreed timeframes, evidencing an effective risk management lifecycle.

  • ✓

    Regular reporting of security performance metrics to the board.

    Why this is correct

    Regular reporting of security performance metrics to the board demonstrates that governance operates as a continuous oversight mechanism, not a one-off exercise. It satisfies the stem's requirement for an indicator of effectiveness by evidencing accountability at the highest level, enabling directors to challenge risk decisions and align security investment with business objectives.

  • ✗

    High completion rate for security awareness training.

    Why it's wrong here

    Completion rates measure training delivery, not whether behaviour changed or risk fell; governance effectiveness shows in reduced incidents and policy compliance, not attendance. It tempts because awareness training is a mandated control, and high uptake would be the right metric when evidencing programme reach to auditors.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.