Certified Information Security Manager (CISM)Information Security ProgramHard

A CISO is presenting the information security program's performance to the steering committee. One committee member asks about the 'value for money' of recent security investments. Which of the following metrics would BEST demonstrate the financial value derived from the security program?

  1. AEmployee completion rates for security awareness training.
  2. BNumber of critical vulnerabilities identified and remediated.
  3. CMean Time To Detect (MTTD) and Mean Time To Respond (MTTR).
  4. DAnnualized Loss Expectancy (ALE) reduction due to implemented controls.
Show answer & explanation

Correct answer: D. Annualized Loss Expectancy (ALE) reduction due to implemented controls.

Annualized Loss Expectancy (ALE) quantifies the financial impact of risks over a year. Demonstrating the reduction in ALE directly translates security investments into averted financial losses, which is the most direct way to show 'value for money' to a committee focused on financial return.

Why the other options are wrong

  • A. Training completion rates measure compliance with a program, not the financial value or ROI of the security program itself.
  • B. Vulnerability remediation is a technical achievement, but it doesn't directly quantify the financial value or averted losses.
  • C. MTTD and MTTR are operational efficiency metrics, not direct measures of financial value or ROI.

Annualized Loss Expectancy (ALE) Reduction

A quantitative metric that estimates the financial savings achieved by implementing security controls, calculated by comparing the ALE before and after control implementation.

  • Directly quantifies financial risk reduction.
  • Key for demonstrating ROI of security.
  • Relevant for executive and financial stakeholders.

Memory trick: ALE Avoids All Loss.

More Information Security Program questions