Certified Information Security Manager (CISM)Information Security GovernanceMedium

During a strategic planning session, the board of directors expresses concern that the organization's information security investments are not clearly demonstrating value to the business. Which of the following actions should the CISO take to BEST address this concern?

  1. APresent a detailed breakdown of all security technologies purchased and their technical specifications.
  2. BRelate security investments to quantifiable business outcomes, such as reduced financial loss from incidents or improved compliance ratings.
  3. CBenchmark the organization's security spending against industry averages and present the comparison.
  4. DInitiate a comprehensive risk assessment to identify new threats and justify further security budget increases.
Show answer & explanation

Correct answer: B. Relate security investments to quantifiable business outcomes, such as reduced financial loss from incidents or improved compliance ratings.

To demonstrate value to the board, the CISO should relate security investments to quantifiable business outcomes. This approach translates technical security into terms that resonate with business leaders, showing how security contributes directly to financial stability, operational continuity, and regulatory adherence.

Why the other options are wrong

  • A. Technical specifications do not inherently demonstrate business value to the board.
  • C. Benchmarking shows how spending compares, but not the direct value or ROI of those investments to the specific business.
  • D. Justifying further increases is not addressing the current concern about the value of existing investments; it's asking for more without proving current worth.

Measuring InfoSec Value

The process of quantifying and communicating the tangible and intangible benefits of information security investments in terms of business outcomes, risk reduction, and strategic enablement.

  • Translates security into business language.
  • Focuses on ROI and risk mitigation.
  • Essential for executive buy-in and continued funding.

Memory trick: Show the board how security isn't just a cost, but a guardian of the gold.

More Information Security Governance questions