CISM - Information Security Program (33% of the exam) - Section 3.5

Define and monitor information security programme metrics to measure effectiveness and support decision-making.

Define security metrics and key performance indicators (KPIs) that measure programme effectiveness and support evidence-based decision-making, including balanced scorecard approaches. Distinguish between leading indicators that predict future risk exposure and lagging indicators that report on past performance.

KPIsSecurity metricsBalanced scorecardProgramme effectiveness

Practice question for this objective

Free sampleInformation Security Programmedium

An information security manager is defining a new set of key performance indicators for the programme and wants each one to genuinely support management decision-making. A colleague proposes adopting whichever measures the security tools can export most easily. What should most strongly determine which measures become the programme's key performance indicators?

  • AWhether each measure is derived from a defined programme objective so that movement in it informs a management decision Correct
  • BWhether each measure can be generated automatically by existing security tooling without manual collection or calculation effort
  • CWhether each measure produces a number that has been rising steadily and can be presented as evidence of programme progress
  • DWhether each measure matches an indicator that comparable organisations in the same sector are already reporting to their own boards
Key performance indicators should be selected because they trace to a programme objective and inform a decision, not because the data is convenient or favourable. A key performance indicator exists to inform a management decision against a defined objective. Selecting measures by data availability, favourable trend or peer imitation detaches the metric from any decision it should support, eroding the value of the indicator set.

Why A is correct: A key performance indicator earns its place by tracing to a programme objective and informing a decision, which keeps the metric set purposeful rather than driven by whatever data is convenient.

Why B is wrong: Automated collection lowers reporting cost and improves consistency, which makes it attractive, but ease of extraction says nothing about whether the measure informs any management decision.

Why C is wrong: An upward trend is easy to narrate to stakeholders, but selecting measures because they look favourable biases the set and undermines its value for honest decision-making.

Why D is wrong: Aligning with peer practice can aid benchmarking and seems credible, but a metric others use may not map to this organisation's own objectives or decisions.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • A key performance indicator that reports the percentage of security incidents resolved within the agreed service target

    Why it is wrong: This is a performance indicator that looks backward at how efficiently incidents were handled; it measures activity quality but does not signal that risk is rising toward a threshold.

  • The financial perspective, reporting the security budget consumed and the cost incurred per protected endpoint across the period

    Why it is wrong: The financial perspective belongs on a complete scorecard, which is why it tempts, but cost figures describe spending rather than the programme's capacity to develop future capability.

  • Replace the financial perspective with a single composite security score derived by averaging all available operational measures

    Why it is wrong: A composite average is tempting as a tidy headline, but collapsing measures into one number hides the distinct perspectives the balanced scorecard exists to keep visible and still ignores improvement and stakeholders.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.