712-50 Question 232
Single answerDevelop a plan to continuously measure the effectiveness of the information systems projects to ensure optimal system performanceA newly appointed CISO inherits several in-flight information systems projects, including an IAM upgrade, SIEM optimization, and endpoint detection rollout. The board has asked for assurance that these projects are not only being delivered on time and within budget, but are also improving operational performance and reducing security risk after deployment. The CISO wants a sustainable way to continuously measure project effectiveness and identify underperforming initiatives early. Which approach is MOST appropriate?
- A
Establish a benefits-realization framework with predefined KPIs, KRIs, service performance baselines, and periodic post-implementation reviews tied to business and risk objectives
- B
Track project success primarily through milestone completion, budget variance, and the number of security tools deployed across the environment
- C
Require each project manager to submit a quarterly narrative summary describing perceived improvements in security posture and system performance
- D
Measure effectiveness by comparing the organization’s annual audit findings before and after project completion, and defer further review until the next audit cycle
Show answer and explanation
Correct answer: A
Explanation
The best answer is to implement a continuous measurement model grounded in benefits realization, operational metrics, and risk-based governance. At the CCISO level, leaders are expected to ensure that information systems projects deliver measurable business and security outcomes, not just complete technical implementation. Good practice is to define success criteria before deployment, establish current-state baselines, monitor KPIs and KRIs after rollout, and conduct recurring post-implementation reviews to confirm sustained value.
Relevant best practices appear across widely used governance and security frameworks. COBIT emphasizes aligning goals, measuring performance, and realizing benefits through governance objectives and metrics. NIST Cybersecurity Framework encourages use of profiles, measurement, and continuous improvement tied to business needs and risk management outcomes. NIST SP 800-55 provides guidance on performance measurement for information security programs, including the need for meaningful, repeatable metrics. In practice, a CISO should combine delivery metrics with outcome metrics such as mean time to detect, mean time to respond, privileged access exception rates, false-positive reduction, endpoint stability, identity-related service availability, and user-impact indicators. This creates an evidence-based mechanism to continuously measure effectiveness and ensure optimal system performance.
- A. Correct.
Correct. This is the strongest approach because it measures both delivery performance and operational outcomes over time. A benefits-realization framework aligns project metrics to intended business value, security outcomes, and system performance. Predefined KPIs and KRIs enable continuous measurement rather than one-time assessment. Baselines are essential so the organization can determine whether latency, uptime, alert fidelity, incident response times, privileged access violations, or other relevant measures have actually improved. Periodic post-implementation reviews help validate whether expected benefits were achieved and whether corrective actions are needed.
- B. Incorrect.
Incorrect. Milestones, budget variance, and deployment counts are project management indicators, not sufficient indicators of effectiveness. A project can be on time and on budget yet fail to improve detection capability, system resilience, user experience, or risk reduction. This option reflects the common misconception that delivery efficiency equals business or security effectiveness.
- C. Incorrect.
Incorrect. Narrative summaries may provide useful context, but they are subjective and difficult to trend consistently across projects. Without objective, predefined measures and baselines, leadership cannot reliably compare initiatives or detect degradation in system performance. This approach also depends too heavily on individual interpretation and reporting quality.
- D. Incorrect.
Incorrect. Audit findings can be a lagging indicator and are too infrequent to support continuous measurement. Annual audit results may miss operational issues such as false-positive rates, authentication failures, endpoint performance degradation, or delayed incident response. Deferring review until the next audit cycle undermines timely governance and corrective action.