StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 3: Information security program

Information security program metrics: KPIs, KRIs and maturity

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Metrics tell you and your stakeholders whether the information security program is working. Without them, the program cannot show value, justify budget or spot problems early, and decisions are made on opinion rather than evidence. The challenge is not collecting numbers, which security tools produce in huge volumes, but choosing measures that answer real questions for each audience and lead to action.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan