Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is presenting the information security strategy to the board of directors. During the presentation, a board member asks how the organization measures the effectiveness of its security investments in tangible business terms. Which of the following metrics would BEST address this concern?

  1. AThe Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for incidents.
  2. BThe percentage reduction in estimated financial losses from cyber incidents.
  3. CThe number of security patches applied per month.
  4. DThe total number of security controls implemented across the enterprise.
Show answer & explanation

Correct answer: B. The percentage reduction in estimated financial losses from cyber incidents.

Boards are primarily concerned with financial impact and risk reduction. Communicating the percentage reduction in estimated financial losses due to cyber incidents directly translates security efforts into quantifiable business value, demonstrating how investments mitigate potential financial harm and protect the organization's bottom line.

Why the other options are wrong

  • A. These are important operational metrics for incident response but don't directly quantify the financial value of security investments.
  • C. This is an operational metric that doesn't directly convey business value to the board.
  • D. The number of controls indicates activity but not necessarily the effectiveness or financial benefit of those controls.

Strategic Security Metrics

Key performance indicators (KPIs) used to measure and communicate the effectiveness and business value of information security efforts to executive leadership and the board of directors.

  • Focus on business impact and risk.
  • Translate security into financial or strategic terms.
  • Inform decision-making and resource allocation.

Memory trick: Show the board the money saved, not just the locks.

More Information Security Governance questions