Certified Information Security Manager (CISM)Information Security GovernanceHard
A CISO is tasked with evaluating the effectiveness of the organization's current information security governance. Which of the following metrics would provide the BEST insight into the strategic alignment of information security with business objectives?
- ANumber of security incidents responded to per quarter.
- BPercentage of business projects that included security requirements from inception.
- CAverage time taken to patch critical vulnerabilities.
- DTotal expenditure on security technologies compared to the previous year.
Show answer & explanationAnswer & explanation
Correct answer: B. Percentage of business projects that included security requirements from inception.
Strategic alignment means security is integrated into business processes at the earliest stages. The percentage of business projects including security requirements from inception directly measures how well security is embedded into and supports new business initiatives, indicating strategic alignment.
Why the other options are wrong
- A. This is an operational metric showing incident response efficiency, not strategic alignment with business objectives.
- C. This is a tactical operational metric related to vulnerability management, not a measure of strategic alignment.
- D. While budget is related to security, it doesn't directly measure *how* security supports or integrates with business strategy, only the level of investment.
Strategic Alignment Metrics
Key performance indicators (KPIs) used to measure the extent to which information security strategies, objectives, and investments are integrated with and contribute to the organization's overall business goals.
- Focus on business-centric outcomes.
- Measure proactive integration, not just reactive security.
- Examples include security in project lifecycles, risk-based decision-making.
Memory trick: To align strategically, count security's presence from project's start.