CISM - Information Security Program - Section 3.5

Define and monitor information security programme metrics to measure effectiveness and support decision-making.

Define security metrics and key performance indicators (KPIs) that measure programme effectiveness and support evidence-based decision-making, including balanced scorecard approaches. Distinguish between leading indicators that predict future risk exposure and lagging indicators that report on past performance.

KPIsSecurity metricsBalanced scorecardProgramme effectiveness

Practice question for this objective

Free sampleInformation Security Programmedium

An information security manager is defining a new set of key performance indicators for the programme and wants each one to genuinely support management decision-making. A colleague proposes adopting whichever measures the security tools can export most easily. What should most strongly determine which measures become the programme's key performance indicators?

  • AWhether each measure is derived from a defined programme objective so that movement in it informs a management decision Correct
  • BWhether each measure can be generated automatically by existing security tooling without manual collection or calculation effort
  • CWhether each measure produces a number that has been rising steadily and can be presented as evidence of programme progress
  • DWhether each measure matches an indicator that comparable organisations in the same sector are already reporting to their own boards
Key performance indicators should be selected because they trace to a programme objective and inform a decision, not because the data is convenient or favourable. A key performance indicator exists to inform a management decision against a defined objective. Selecting measures by data availability, favourable trend or peer imitation detaches the metric from any decision it should support, eroding the value of the indicator set.

Why A is correct: A key performance indicator earns its place by tracing to a programme objective and informing a decision, which keeps the metric set purposeful rather than driven by whatever data is convenient.

Why B is wrong: Automated collection lowers reporting cost and improves consistency, which makes it attractive, but ease of extraction says nothing about whether the measure informs any management decision.

Why C is wrong: An upward trend is easy to narrate to stakeholders, but selecting measures because they look favourable biases the set and undermines its value for honest decision-making.

Why D is wrong: Aligning with peer practice can aid benchmarking and seems credible, but a metric others use may not map to this organisation's own objectives or decisions.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.