Certified Information Security Manager (CISM)Information Security Risk ManagementEasy
A Chief Information Security Officer (CISO) is presenting the current state of information security to the board of directors. The board is primarily concerned with the financial implications of cyber risks and the return on security investments. Which of the following metrics would be MOST effective for the CISO to present?
- APercentage of employees who completed security awareness training.
- BRisk-adjusted Return on Investment (ROI) for security projects.
- CNumber of critical vulnerabilities identified per month.
- DMean Time To Detect (MTTD) security incidents.
Show answer & explanationAnswer & explanation
Correct answer: B. Risk-adjusted Return on Investment (ROI) for security projects.
The board of directors is concerned with financial implications and ROI. Risk-adjusted ROI directly addresses the financial value and effectiveness of security investments in business terms, making it the most effective metric for this audience.
Why the other options are wrong
- A. Training completion is a compliance metric, not directly addressing financial implications or ROI for the board.
- C. Number of vulnerabilities is a technical metric and doesn't directly translate to financial impact or ROI for the board.
- D. MTTD is an operational metric for security teams, not primarily a financial metric for the board.
Risk-adjusted ROI for Security
A financial metric that evaluates the return on investment for security projects, taking into account the reduction in risk (e.g., avoided losses) achieved by the investment.
- Quantifies the financial benefit of security investments.
- Considers risk reduction as part of the return.
- Useful for communicating value to business stakeholders like the board.
Memory trick: ROI is the board's key.