Isaca CISM Question Answer
Which of the following is MOST difficult to measure following an information security breach?
Reputational damage
Human resource costs
Regulatory sanctions
Replacement efforts
Reputational damage is often intangible, subjective, and hard to quantify, making it the most challenging aspect to measure.
“Reputation impact is difficult to quantify and may have long-term effects that are not immediately apparent.”
— CISM Review Manual 15th Edition, Chapter 4: Incident Management, Section: Post-incident Analysis*
ISACA practice questions highlight that reputational damage is uniquely challenging to measure accurately.
TESTED 23 Dec 2025
Copyright © 2014-2025 ACE4Sure. All Rights Reserved