Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is reviewing the information security program's performance metrics. The current metrics focus heavily on technical indicators such as the number of vulnerabilities found, patches applied, and intrusion attempts blocked. While these are useful, the board of directors is requesting more strategic insights into the program's overall effectiveness and business value. Which of the following metrics would BEST address the board's request?

  1. ANumber of security incidents per business unit and their associated financial impact.
  2. BPercentage of employees completing security awareness training.
  3. CMean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for critical incidents.
  4. DNumber of critical vulnerabilities remediated within service level agreements (SLAs).
Show answer & explanation

Correct answer: A. Number of security incidents per business unit and their associated financial impact.

The board is interested in strategic insights and business value. Metrics tied to financial impact and business unit performance directly translate security outcomes into terms relevant to business operations and profitability, providing a clear picture of the program's value.

Why the other options are wrong

  • B. Training completion rates are a process metric, indicating activity, but not directly measuring the effectiveness or business impact of the program.
  • C. MTTD and MTTR are important operational metrics but less directly represent the overall business value compared to financial impact.
  • D. Vulnerability remediation within SLAs is a technical operational metric, important for security teams, but less strategic for board-level business value discussions.

Strategic Security Metrics

Key performance indicators (KPIs) that measure the overall effectiveness of the information security program in achieving business objectives and managing enterprise risk, often expressed in business-relevant terms.

  • Provide insights for executive decision-making.
  • Focus on business impact and risk reduction.
  • Translate technical jargon into business language (e.g., financial impact).

Memory trick: The board wants to see security's impact on the bottom line, not just technical details.

More Information Security Program questions