Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
An organization is evaluating the effectiveness of its information security awareness training program. Post-training phishing simulations show a 15% click-through rate, which is higher than the industry average of 10%. The information security manager needs to report this to senior management and recommend improvements. Which of the following metrics would be MOST useful to present alongside the click-through rate to provide a comprehensive view of the program's impact?
- ANumber of security incidents reported by employees after training.
- BCost of the security awareness training program.
- CPercentage of employees who completed the training module.
- DTime taken for employees to complete the training.
Show answer & explanationAnswer & explanation
Correct answer: A. Number of security incidents reported by employees after training.
While click-through rate shows susceptibility, the ultimate goal of security awareness is to reduce actual security incidents. Reporting the number of security incidents (or lack thereof) post-training directly demonstrates the real-world impact and effectiveness of the program in mitigating risk, providing a more comprehensive view to senior management.
Why the other options are wrong
- B. The cost is a budget metric, not a direct measure of program effectiveness in reducing risk.
- C. Completion rate indicates reach but not necessarily understanding or behavioral change.
- D. Time taken is an engagement metric, not a direct measure of security outcome or risk reduction.
Security Program Metrics
Quantifiable measures used to assess the performance, effectiveness, and maturity of an information security program.
- Should align with business objectives.
- Include operational, technical, and management metrics.
- Used for reporting, decision-making, and continuous improvement.
Memory trick: Measure what matters: outcomes over efforts.