New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 3 Question 98 Discussion

Actual exam question for Isaca's CISM exam
Question #: 98
Topic #: 3
[All CISM Questions]

An organization is implementing an information security governance framework. To communicate the program's effectiveness to stakeholders, it is MOST important to establish:

Show Suggested Answer Hide Answer
Suggested Answer: D

= Establishing metrics for each milestone is the best way to communicate the program's effectiveness to stakeholders, as it provides a clear and measurable way to track the progress, performance, and outcomes of the information security governance framework. Metrics are quantifiable indicators that can be used to evaluate the achievement of specific objectives, goals, or standards. Metrics can also help to demonstrate the value, benefits, and return on investment of the information security program, as well as to identify and address the gaps, issues, or risks. Metrics for each milestone should be aligned with the organization's strategy, vision, and mission, as well as with the expectations and needs of the stakeholders. Metrics for each milestone should also be SMART (specific, measurable, achievable, relevant, and time-bound), as well as consistent, reliable, and transparent.

The other options are not as important as establishing metrics for each milestone, as they do not provide a comprehensive and holistic way to communicate the program's effectiveness to stakeholders. A control self-assessment (CSA) process is a technique to involve the staff in assessing the design, implementation, and effectiveness of the information security controls. It can help to increase the awareness, ownership, and accountability of the staff, as well as to identify and mitigate the risks. However, a CSA process alone is not enough to communicate the program's effectiveness to stakeholders, as it does not measure the overall performance or maturity of the information security program. Automated reporting to stakeholders is a method to provide timely, accurate, and consistent information to the stakeholders about the status, results, and issues of the information security program. It can help to facilitate the communication, collaboration, and decision making among the stakeholders, as well as to ensure the compliance and transparency of the information security program. However, automated reporting alone is not enough to communicate the program's effectiveness to stakeholders, as it does not evaluate the achievement or impact of the information security program. A monitoring process for the security policy is a process to ensure that the security policy is implemented, enforced, and reviewed in accordance with the organization's objectives, standards, and regulations. It can help to maintain the relevance, adequacy, and effectiveness of the security policy, as well as to incorporate the feedback, changes, and improvements. However, a monitoring process alone is not enough to communicate the program's effectiveness to stakeholders, as it does not cover the other aspects of the information security program, such as governance, risk management, incident management, or business continuity.Reference=

CISM Review Manual, 16th Edition, ISACA, 2022, pp. 211-212, 215-216, 233-234, 237-238.

CISM Questions, Answers & Explanations Database, ISACA, 2022, QID 1018.

CISM domain 1: Information security governance [Updated 2022], Infosec,1.

Key Performance Indicators for Security Governance, Part 1, ISACA Journal, Volume 6, 2020,2.


Contribute your Thoughts:

0/2000 characters
Anthony
2 months ago
Surprised no one mentioned risk assessments!
upvoted 0 times
...
Juliana
2 months ago
Automated reporting (B) seems more efficient though.
upvoted 0 times
...
Keneth
3 months ago
Totally agree, metrics are essential!
upvoted 0 times
...
Margurite
3 months ago
Wait, are we sure metrics alone are enough?
upvoted 0 times
...
Caprice
3 months ago
I think D is key for tracking progress.
upvoted 0 times
...
Dusti
3 months ago
I keep thinking about the importance of a monitoring process for the security policy; it could help ensure compliance, but does it really communicate effectiveness?
upvoted 0 times
...
Dana
4 months ago
The control self-assessment process sounds familiar, but I feel like it might be more about internal checks rather than communicating with stakeholders directly.
upvoted 0 times
...
Mee
4 months ago
I remember discussing automated reporting in class, and it seems like a good way to keep stakeholders informed, but I wonder if it really captures the program's effectiveness.
upvoted 0 times
...
Skye
4 months ago
I think establishing metrics for each milestone is crucial for showing progress, but I'm not entirely sure if that's the most important aspect.
upvoted 0 times
...
Carlee
4 months ago
This is a tricky one. I'm leaning towards the monitoring process for the security policy, but I'm not totally confident that's the right answer. I'll need to double-check my understanding of the question and the options before submitting my final answer.
upvoted 0 times
...
Leigha
4 months ago
Okay, I've got a strategy for this. I'll start by eliminating any options that don't directly address communicating effectiveness, then compare the remaining choices to see which one is the MOST important. Gotta make sure I pick the best answer here.
upvoted 0 times
...
Tegan
5 months ago
Hmm, I'm a bit unsure about this one. There are a few options that seem relevant, but I'm not entirely sure which one is the MOST important. I'll need to carefully read through each choice and think about how they relate to communicating effectiveness.
upvoted 0 times
...
Carrol
5 months ago
This seems like a straightforward question about establishing an effective information security governance framework. I think the key is to focus on communicating the program's effectiveness to stakeholders, so I'll likely go with the option that best addresses that.
upvoted 0 times
...
Iluminada
7 months ago
Metrics for each milestone? Sounds like a lot of work, but hey, at least it'll keep the boss happy. I'll just copy-paste the numbers and call it a day.
upvoted 0 times
...
Carol
7 months ago
Monitoring the security policy is key. How else are we gonna make sure it's actually being followed? Might as well just wing it if we don't have that in place.
upvoted 0 times
...
Reita
7 months ago
Hold up, what about a control self-assessment process? That'll help us identify any gaps in our security framework. Gotta cover all the bases, you know?
upvoted 0 times
Pedro
5 months ago
User 3: Metrics for each milestone would also be helpful in demonstrating the progress of the information security governance framework.
upvoted 0 times
...
Alecia
5 months ago
User 2: We should also consider automated reporting to stakeholders to keep them informed about the program's effectiveness.
upvoted 0 times
...
Winifred
7 months ago
User 1: I agree, a control self-assessment process is crucial for identifying gaps in our security framework.
upvoted 0 times
...
...
Sheridan
8 months ago
Automated reporting to stakeholders sounds like the most efficient option. Who has time for manual reporting these days?
upvoted 0 times
Elfriede
7 months ago
Having automated reporting will make it easier to track and communicate the effectiveness of the security program.
upvoted 0 times
...
Leonor
7 months ago
I agree, manual reporting can be time-consuming and prone to errors.
upvoted 0 times
...
Malika
7 months ago
Automated reporting is definitely the way to go. It saves time and ensures accuracy.
upvoted 0 times
...
...
Gerry
8 months ago
But wouldn't automated reporting to stakeholders also be important for real-time updates?
upvoted 0 times
...
Micheal
8 months ago
I think establishing metrics for each milestone is the way to go. That'll give us a clear way to measure progress and communicate it to stakeholders.
upvoted 0 times
Geoffrey
7 months ago
I think automated reporting to stakeholders would also be helpful in communicating the effectiveness of the program.
upvoted 0 times
...
Iluminada
7 months ago
I agree, having metrics for each milestone will definitely help us track our progress.
upvoted 0 times
...
...
Louisa
8 months ago
I agree with Rikki. Metrics will show stakeholders the progress and effectiveness of the program.
upvoted 0 times
...
Rikki
9 months ago
I think the most important thing is to establish metrics for each milestone.
upvoted 0 times
...

Save Cancel