Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is presenting the annual information security program report to the executive board. The board members are primarily interested in the financial impact of security risks and the return on investment (ROI) of security expenditures. Which type of metric should the CISO emphasize to best meet the board's expectations?
- ABusiness-aligned metrics, such as averted financial losses and risk reduction percentages.
- BCompliance metrics, such as the number of policy violations and audit findings.
- CTechnical metrics, such as the number of patches deployed and vulnerability scan results.
- DOperational metrics, such as incident response times and security tool uptime.
Show answer & explanationAnswer & explanation
Correct answer: A. Business-aligned metrics, such as averted financial losses and risk reduction percentages.
Executive boards are typically concerned with the organization's financial health and strategic objectives. Business-aligned metrics, which translate security efforts into financial terms like averted losses or risk reduction, directly address their interest in financial impact and ROI.
Why the other options are wrong
- B. While important, compliance metrics don't directly quantify financial impact or ROI in the way business-aligned metrics do.
- C. Technical metrics are too granular for an executive board primarily focused on financial impact.
- D. Operational metrics provide insight into daily security operations but do not directly address financial impact or ROI for the board.
Business-Aligned Security Metrics
Metrics that translate security performance into terms relevant to business objectives, such as financial impact, risk reduction, and operational efficiency, to inform executive decision-making.
- Focus on financial impact and ROI.
- Relevant for executive stakeholders.
- Demonstrates business value of security.
Memory trick: Business Benefits Bring Board Buy-in.