CISM - Information Security Program - Section 3.11

Communicate information security programme status and outcomes to stakeholders through appropriate reporting.

Communicate information security programme status and outcomes to stakeholders through a security dashboard, executive reporting, and board reporting tailored to each audience. Choose metrics and language that translate technical programme results into business terms, enabling informed governance decisions at every level.

Executive reportingSecurity dashboardBoard reportingProgramme communications

Practice question for this objective

Free sampleInformation Security Programmedium

An information security manager is selecting metrics to report monthly to the board. Several candidate measures are proposed, including the number of firewall rule changes, the percentage of staff who completed security awareness training, the count of malware files quarantined, and the average time to deploy operating system patches. The board has asked for metrics that demonstrate whether the security programme is achieving its stated objectives. Which characteristic should most influence which measures are promoted to the board report?

  • AWhether each measure links to a defined programme objective and supports a decision the recipient is positioned to make Correct
  • BWhether each measure can be collected automatically from existing tools without additional manual effort by the security team
  • CWhether each measure produces a number that has risen or fallen since the previous reporting period
  • DWhether each measure is already tracked by peer organisations in the same industry sector
Board-level security metrics should be chosen for their link to programme objectives and their ability to support governance decisions, not for ease of collection or trend visibility. A metric earns its place in management reporting when it connects a measured value to a defined objective and enables the recipient to decide or act; measures that are merely easy to collect or that simply show movement do not support decision-making at board level.

Why A is correct: Board metrics must tie to objectives and inform governance decisions; relevance to the audience and to a stated outcome is what makes a measure worth reporting at that level.

Why B is wrong: Ease of automated collection is operationally convenient, but a measure that is cheap to gather still fails the board if it does not relate to a programme objective the board cares about.

Why C is wrong: A visible trend is tempting because movement looks like insight, but direction of change is meaningless if the underlying measure is not tied to an objective the board is accountable for.

Why D is wrong: Peer benchmarking has value for context, but copying a peer's measure does not guarantee it reflects this organisation's own programme objectives or supports its decisions.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.