What is most important when selecting CISM key risk indicators?

Information Security Risk Management
Answer Correct answer: B — Choose KRIs that align with business processes so they measure the level of risk against what the organization most cares about.

When determining key risk indicators (KRIs) for use in an information security program it is MOST important to select:

  1. KRIs that track both short-term and long-term performance.
  2. KRIs that align with business processes. Correct Answer
  3. KRIs that are quantifiable.
  4. as many KRIs as possible to catch risk events from the broadest areas.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CISM expects you to see that quantifiability (C) is useful but subordinate to business-process alignment (B), because a KRI must monitor real risk to operational objectives.

For CISM, selecting key risk indicators that align with business processes is more important than choosing quantifiable metrics. The community unanimously agreed on option B because alignment ensures KRIs are relevant and measure risks tied to critical operations.

Choosing option C (quantifiable) is the classic trap; a numeric indicator can be irrelevant to the business, whereas a KRI tied to a critical process gives management the early warning needed for risk decisions.

Community Discussion (4 comments)

fac161f 👍 1 Selected: B
Not seeing how C is a better answer.
koala_lay 👍 3 Selected: B
B. KRIs that align with business processes: KRIs should be selected based on their ability to effectively monitor and measure the risks associated with the organization's critical business processes. This ensures that the KRIs are directly relevant to the organization's operations and priorities, and can provide meaningful insights for risk management.
sausageman 👍 1 Selected: B
B. KRIs that align with business processes.
shootnot 👍 1 Selected: B
C is incorrect because if KRI is quantifiable that's good but not good enough unless its B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is the correct CISM answer because a KRI has value only when it directly reflects the risk exposure of the organization's critical business processes. Commenter 1 notes that selecting KRIs based on their ability to monitor and measure the risks associated with critical business operations ensures the indicators are directly relevant to organizational priorities. The word "MOST important" in the question pushes the focus beyond basic measurement: a KRI must be relevant and meaningful to business decisions before its numerical precision matters.

Why the Other Options Are Wrong

Option C is a tempting choice but incorrect in this ranked question because quantifiability is a supporting attribute, not the primary purpose of KRIs. Commenter 4 explicitly says a quantifiable KRI is "good, but not good enough" unless it also aligns with business processes. Option A is also reasonable but secondary, as KRIs already need to capture emerging risk trends, and choosing both short- and long-term indicators does not guarantee alignment with critical operations. Option D is harmful because flooding the security program with too many KRIs dilutes focus and can create alert fatigue rather than providing strategic risk insight.

Community Comment Notes

The comment thread is unanimous in selecting B, and no dissent appears among the comments. The most useful comment (likes=3) explains why B is best by tying KRI selection to the organization's critical business processes and operations. Several users reference the obvious competitor, option C, but clarify that quantifiability alone does not make an indicator effective; it must also be aligned to the business. This supports the CISM mindset that key risk indicators are tools for management to see risk against business objectives, not merely generic metrics.

Official Reference

Exam Strategy

When you see "MOST important" on a CISM KRI question, first eliminate options that describe measurement mechanics or volume. The answer will almost always be the option that connects the indicator to the business, as business alignment is what makes risk information actionable.

Frequently Asked Questions

Why is B more important than C when choosing CISM KRIs?

Because a KRI is only useful if it tracks risk to critical business objectives; measurability helps but does not ensure relevance to management decisions.

Why is selecting 'as many KRIs as possible' wrong for CISM?

Too many indicators create alert fatigue and dilute focus; the best KRI program tracks only indicators that are meaningful to critical business processes.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide