712-50 Question 403
Single answerDefine key performance indicators and measure effectiveness on continuous basisA newly appointed CISO is reporting to the board on the effectiveness of the security operations program. The board previously received monthly dashboards showing the number of blocked attacks, total vulnerabilities found, and total security events, but directors said the reports did not help them understand whether the program was improving risk reduction over time. The CISO wants to define a KPI approach that can be measured continuously and tied to business outcomes. Which of the following is the BEST KPI design choice?
- A
Track the monthly total number of IDS alerts and compare it to the previous month to show whether the security team is working harder.
- B
Track the percentage of critical vulnerabilities remediated within the approved SLA, trend it quarterly by business unit, and correlate exceptions with asset criticality and risk acceptance decisions.
- C
Track the total number of security tools deployed across the enterprise and increase the target each year to demonstrate program maturity.
- D
Track the number of phishing emails received by the organization and use decreases as the primary measure of security awareness effectiveness.
Show answer and explanation
Correct answer: B
Explanation
Effective KPIs for a CISO should be aligned to business objectives, measurable consistently over time, and focused on outcomes rather than raw activity. In this scenario, the board wants evidence of improving risk reduction, so the best KPI is one that shows whether high-risk issues are being reduced within defined tolerance levels. Percentage of critical vulnerabilities remediated within SLA is stronger than simple counts because it normalizes performance, supports trending, and can be tied directly to policy, asset criticality, and accepted risk.
This approach is consistent with common security governance and performance measurement practices found in frameworks such as NIST Cybersecurity Framework, NIST SP 800-55 (Performance Measurement Guide for Information Security), and ISO/IEC 27004, which emphasize defining meaningful measures tied to objectives, monitoring them regularly, and using them to support decision-making and continuous improvement. In executive reporting, leading and lagging indicators should help answer whether controls are effective, whether risk is within appetite, and where management action is required. Option 2 best meets those criteria.
- A. Incorrect.
Incorrect. Raw alert volume is typically an activity or operational load metric, not a strong KPI for effectiveness. Alert counts can rise or fall for reasons unrelated to security performance, such as tuning changes, new log sources, seasonality, or attacker behavior. This option also focuses on how busy the team is rather than whether risk is being reduced or controls are performing effectively.
- B. Correct.
Correct. This is the strongest KPI because it is outcome-oriented, measurable on a continuous basis, aligned to risk tolerance, and meaningful to leadership. Measuring the percentage of critical vulnerabilities remediated within SLA reflects whether the organization is managing exposure in a timely manner. Trending by business unit supports accountability, and correlating with asset criticality and formal risk acceptance helps distinguish justified exceptions from poor performance. This creates a KPI that is actionable, risk-based, and useful for governance.
- C. Incorrect.
Incorrect. The number of tools deployed is a capability or investment metric, not an effectiveness KPI. More tools do not necessarily produce better security outcomes and may even increase complexity. This reflects a common misconception that technology quantity equals maturity. Boards generally need measures tied to risk reduction, resilience, and control performance rather than inventory growth.
- D. Incorrect.
Incorrect. The number of phishing emails received is largely outside the organization's control and is driven by external threat activity. Using it as the primary measure of awareness effectiveness is misleading. A better awareness-related KPI would focus on controllable outcomes, such as reporting rates, click-through rates, or credential submission rates over time, ideally segmented by role or business unit.