What is Most Important When Establishing Security Metrics for Executive Reporting?
What is the MOST important consideration when establishing metrics for reporting to the information security strategy committee?
Community Votes
57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests governance prioritization where candidates often mistakenly choose baseline establishment instead of recognizing that executive buy-in and cultural alignment dictate metric relevance.
Establishing effective security metrics requires prioritizing business alignment over technical setup, with community consensus favoring cultural and risk appetite alignment as the critical first step.
Option C (Agreeing on baseline values) is frequently selected because baselines seem foundational, but without first ensuring metrics match leadership’s risk appetite and organizational culture, baselines lack strategic purpose.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Aligning metrics with organizational culture ensures they reflect the company’s risk appetite, strategic objectives, and executive priorities. Since the information security strategy committee functions as a governance body, metrics must first resonate with leadership values to drive actionable decisions. ISACA emphasizes that security programs succeed only when measurement frameworks are tailored to business context rather than applied generically.Why the Other Options Are Wrong
Benchmarking (A) provides external context but ignores internal strategic fit, making it secondary to alignment. Establishing baselines (C) is a necessary technical step, yet it cannot logically precede defining what the committee actually needs to track. Dashboards (D) are merely presentation tools and do not influence the fundamental design or acceptance of the metrics themselves.Community Comment Notes
Voters highlight that steering committees represent senior management, making cultural alignment the logical prerequisite (Comment 4). Several notes clarify that organizational culture inherently includes risk appetite, which naturally shapes baseline expectations (Comments 2 & 3). The debate underscores CISM’s emphasis on business-first governance over premature technical configuration.Official Reference
Exam Strategy
Always prioritize business alignment and stakeholder relevance over technical implementation steps when governance questions ask for the “MOST important” factor. Ask yourself whether the action directly supports executive decision-making before selecting measurement or reporting options.
Frequently Asked Questions
Why isn't establishing baselines more important?
Baselines require predefined metrics to measure. Without first aligning measurements with leadership priorities, baselines lack strategic relevance and executive buy-in.
How does organizational culture affect security metrics?
Culture dictates risk tolerance and decision-making styles, ensuring metrics focus on business impact rather than purely technical indicators that executives may ignore.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →