What is most important when selecting CISM key risk indicators?
When determining key risk indicators (KRIs) for use in an information security program it is MOST important to select:
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
CISM expects you to see that quantifiability (C) is useful but subordinate to business-process alignment (B), because a KRI must monitor real risk to operational objectives.
For CISM, selecting key risk indicators that align with business processes is more important than choosing quantifiable metrics. The community unanimously agreed on option B because alignment ensures KRIs are relevant and measure risks tied to critical operations.
Choosing option C (quantifiable) is the classic trap; a numeric indicator can be irrelevant to the business, whereas a KRI tied to a critical process gives management the early warning needed for risk decisions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B is the correct CISM answer because a KRI has value only when it directly reflects the risk exposure of the organization's critical business processes. Commenter 1 notes that selecting KRIs based on their ability to monitor and measure the risks associated with critical business operations ensures the indicators are directly relevant to organizational priorities. The word "MOST important" in the question pushes the focus beyond basic measurement: a KRI must be relevant and meaningful to business decisions before its numerical precision matters.
Why the Other Options Are Wrong
Option C is a tempting choice but incorrect in this ranked question because quantifiability is a supporting attribute, not the primary purpose of KRIs. Commenter 4 explicitly says a quantifiable KRI is "good, but not good enough" unless it also aligns with business processes. Option A is also reasonable but secondary, as KRIs already need to capture emerging risk trends, and choosing both short- and long-term indicators does not guarantee alignment with critical operations. Option D is harmful because flooding the security program with too many KRIs dilutes focus and can create alert fatigue rather than providing strategic risk insight.
Community Comment Notes
The comment thread is unanimous in selecting B, and no dissent appears among the comments. The most useful comment (likes=3) explains why B is best by tying KRI selection to the organization's critical business processes and operations. Several users reference the obvious competitor, option C, but clarify that quantifiability alone does not make an indicator effective; it must also be aligned to the business. This supports the CISM mindset that key risk indicators are tools for management to see risk against business objectives, not merely generic metrics.
Official Reference
Exam Strategy
When you see "MOST important" on a CISM KRI question, first eliminate options that describe measurement mechanics or volume. The answer will almost always be the option that connects the indicator to the business, as business alignment is what makes risk information actionable.
Frequently Asked Questions
Why is B more important than C when choosing CISM KRIs?
Because a KRI is only useful if it tracks risk to critical business objectives; measurability helps but does not ensure relevance to management decisions.
Why is selecting 'as many KRIs as possible' wrong for CISM?
Too many indicators create alert fatigue and dilute focus; the best KRI program tracks only indicators that are meaningful to critical business processes.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →