An information security manager is selecting metrics to report monthly to the board. Several candidate measures are proposed, including the number of firewall rule changes, the percentage of staff who completed security awareness training, the count of malware files quarantined, and the average time to deploy operating system patches. The board has asked for metrics that demonstrate whether the security programme is achieving its stated objectives. Which characteristic should most influence which measures are promoted to the board report?
- AWhether each measure links to a defined programme objective and supports a decision the recipient is positioned to make Correct
- BWhether each measure can be collected automatically from existing tools without additional manual effort by the security team
- CWhether each measure produces a number that has risen or fallen since the previous reporting period
- DWhether each measure is already tracked by peer organisations in the same industry sector
Why A is correct: Board metrics must tie to objectives and inform governance decisions; relevance to the audience and to a stated outcome is what makes a measure worth reporting at that level.
Why B is wrong: Ease of automated collection is operationally convenient, but a measure that is cheap to gather still fails the board if it does not relate to a programme objective the board cares about.
Why C is wrong: A visible trend is tempting because movement looks like insight, but direction of change is meaningless if the underlying measure is not tied to an objective the board is accountable for.
Why D is wrong: Peer benchmarking has value for context, but copying a peer's measure does not guarantee it reflects this organisation's own programme objectives or supports its decisions.