Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is presenting the information security strategy to the board of directors. During the presentation, a board member asks how the security team ensures that security investments are aligned with the organization's strategic goals and deliver tangible value. Which of the following metrics would BEST demonstrate this alignment and value?

  1. APercentage reduction in business process downtime due to security incidents.
  2. BTotal budget spent on security technologies and training.
  3. CNumber of security incidents detected and remediated per quarter.
  4. DNumber of security vulnerabilities identified in penetration tests.
Show answer & explanation

Correct answer: A. Percentage reduction in business process downtime due to security incidents.

To demonstrate alignment with strategic goals and tangible value, metrics should directly relate to business outcomes. Reducing business process downtime due to security incidents directly shows how security contributes to operational continuity and efficiency, which are key strategic objectives.

Why the other options are wrong

  • B. Budget spent is an input, not an outcome, and does not demonstrate value or alignment.
  • C. Incident count is an operational metric, not directly showing business value or strategic alignment.
  • D. Vulnerability count is a technical metric and doesn't directly translate to business value in a way the board would immediately understand as strategic alignment.

Strategic Security Metrics

Measurements that demonstrate how information security initiatives support and contribute to the achievement of an organization's overall strategic objectives.

  • Focus on business outcomes, not just technical details.
  • Translate security performance into terms relevant to senior leadership.
  • Help justify security investments and demonstrate ROI.

Memory trick: Show the board how security helps the business bank, not just block hacks.

More Information Security Governance questions