An information security manager is defining a new set of key performance indicators for the programme and wants each one to genuinely support management decision-making. A colleague proposes adopting whichever measures the security tools can export most easily. What should most strongly determine which measures become the programme's key performance indicators?
- AWhether each measure is derived from a defined programme objective so that movement in it informs a management decision Correct
- BWhether each measure can be generated automatically by existing security tooling without manual collection or calculation effort
- CWhether each measure produces a number that has been rising steadily and can be presented as evidence of programme progress
- DWhether each measure matches an indicator that comparable organisations in the same sector are already reporting to their own boards
Why A is correct: A key performance indicator earns its place by tracing to a programme objective and informing a decision, which keeps the metric set purposeful rather than driven by whatever data is convenient.
Why B is wrong: Automated collection lowers reporting cost and improves consistency, which makes it attractive, but ease of extraction says nothing about whether the measure informs any management decision.
Why C is wrong: An upward trend is easy to narrate to stakeholders, but selecting measures because they look favourable biases the set and undermines its value for honest decision-making.
Why D is wrong: Aligning with peer practice can aid benchmarking and seems credible, but a metric others use may not map to this organisation's own objectives or decisions.