CISM - Information Security Program (33% of the exam) - Section 3.11

Communicate information security programme status and outcomes to stakeholders through appropriate reporting.

Communicate information security programme status and outcomes to stakeholders through a security dashboard, executive reporting, and board reporting tailored to each audience. Choose metrics and language that translate technical programme results into business terms, enabling informed governance decisions at every level.

Executive reportingSecurity dashboardBoard reportingProgramme communications

Practice question for this objective

Free sampleInformation Security Programmedium

An information security manager is selecting metrics to report monthly to the board. Several candidate measures are proposed, including the number of firewall rule changes, the percentage of staff who completed security awareness training, the count of malware files quarantined, and the average time to deploy operating system patches. The board has asked for metrics that demonstrate whether the security programme is achieving its stated objectives. Which characteristic should most influence which measures are promoted to the board report?

  • AWhether each measure links to a defined programme objective and supports a decision the recipient is positioned to make Correct
  • BWhether each measure can be collected automatically from existing tools without additional manual effort by the security team
  • CWhether each measure produces a number that has risen or fallen since the previous reporting period
  • DWhether each measure is already tracked by peer organisations in the same industry sector
Board-level security metrics should be chosen for their link to programme objectives and their ability to support governance decisions, not for ease of collection or trend visibility. A metric earns its place in management reporting when it connects a measured value to a defined objective and enables the recipient to decide or act; measures that are merely easy to collect or that simply show movement do not support decision-making at board level.

Why A is correct: Board metrics must tie to objectives and inform governance decisions; relevance to the audience and to a stated outcome is what makes a measure worth reporting at that level.

Why B is wrong: Ease of automated collection is operationally convenient, but a measure that is cheap to gather still fails the board if it does not relate to a programme objective the board cares about.

Why C is wrong: A visible trend is tempting because movement looks like insight, but direction of change is meaningless if the underlying measure is not tied to an objective the board is accountable for.

Why D is wrong: Peer benchmarking has value for context, but copying a peer's measure does not guarantee it reflects this organisation's own programme objectives or supports its decisions.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The maximum volume of security data the team can collect and process within each period, so no available measurement is wasted on the audiences

    Why it is wrong: Tempting because rich data feels valuable, but data-collection capacity is a supply-side constraint, not a governance driver, and flooding decision-makers with everything available defeats the purpose.

  • A detailed log of all security incidents handled during the quarter, including affected hosts and the remediation steps taken by each analyst

    Why it is wrong: Tempting because incident activity feels like proof the programme is working, but operational detail at host and analyst level is management information, not the strategic, decision-oriented content a non-technical board needs.

  • A detailed inventory of every control deployed during the year, demonstrating the technical breadth and sophistication the programme now operates

    Why it is wrong: Tempting because a control inventory shows diligence, but executives judge value by business effect, not by a catalogue of technical mechanisms they cannot evaluate.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.