Certified Information Security Manager (CISM)Information Security Risk ManagementEasy
A Chief Information Security Officer (CISO) is presenting the information security program's annual budget request to the executive board. The board is primarily concerned with the financial impact and return on investment (ROI) of security expenditures. Which of the following metrics would BEST articulate the value of the security program in terms that resonate with the executive board?
- AMean time to resolution (MTTR) for critical incidents.
- BReduction in Annualized Loss Expectancy (ALE) due to security controls.
- CPercentage of employees completing security awareness training.
- DNumber of detected vulnerabilities per month.
Show answer & explanationAnswer & explanation
Correct answer: B. Reduction in Annualized Loss Expectancy (ALE) due to security controls.
Executive boards are typically focused on financial outcomes and risk reduction. Presenting the reduction in Annualized Loss Expectancy (ALE) directly quantifies the financial benefit of security investments by showing how much potential loss has been avoided, aligning with their focus on ROI.
Why the other options are wrong
- A. MTTR is an operational efficiency metric, important for security teams, but less directly impactful for executive financial discussions.
- C. This measures compliance with training, not the financial impact or value of the security program.
- D. This metric indicates activity but doesn't directly translate to financial value or ROI for the board.
Annualized Loss Expectancy (ALE)
The expected monetary loss from a risk over a one-year period, calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO).
- Quantifies financial risk.
- Used for cost-benefit analysis of security controls.
- Helps prioritize risk mitigation efforts.
Memory trick: Speak the language of money, and the board will listen.