Certified Information Security Manager (CISM)Information Security GovernanceHard

A CISO is presenting the annual information security strategy to the board of directors. A board member questions the return on investment (ROI) of recent security expenditures, asking for clearer evidence of their financial benefits. Which of the following actions should the CISO prioritize to address this concern effectively?

  1. ADevelop and present metrics that correlate security investments with reduced business losses from incidents and increased operational efficiency.
  2. BProvide a detailed breakdown of all security technologies purchased and their features.
  3. CCompare the organization's security budget to industry averages and state that it is within acceptable limits.
  4. DCommission an independent audit to validate the effectiveness of all security controls.
Show answer & explanation

Correct answer: A. Develop and present metrics that correlate security investments with reduced business losses from incidents and increased operational efficiency.

To demonstrate ROI, the CISO must translate security benefits into financial terms that resonate with the board. Metrics showing reduced losses from prevented incidents, improved system uptime, or streamlined compliance processes directly address financial benefits and operational efficiency, thereby proving value.

Why the other options are wrong

  • B. Listing features does not equate to demonstrating financial ROI or business value.
  • C. Benchmarking budget against averages shows relative spending, not the specific financial return on the organization's security investments.
  • D. An independent audit validates control effectiveness, but doesn't directly quantify the financial ROI of the investment itself.

Measuring InfoSec ROI

Quantifying the financial return generated by information security investments, typically by demonstrating how security measures reduce costs, prevent losses, or enable business opportunities.

  • Connects security to financial outcomes.
  • Justifies budget allocation.
  • Uses business-centric metrics.

Memory trick: ROI means showing the money saved or gained.

More Information Security Governance questions