712-50 · Question #8
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
The correct answer is B. Alignment of security goals with business goals. Aligning security goals with business goals (B) is the most powerful lever for shaping organizational culture because security becomes embedded in how the business thinks and operates - people adopt secure behaviors when they see security as enabling business success rather…
Question
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
Options
- AAn independent Governance, Risk and Compliance organization
- BAlignment of security goals with business goals
- CCompliance with local privacy regulations
- DSupport from Legal and HR teams
How the community answered
(27 responses)- A19% (5)
- B70% (19)
- C4% (1)
- D7% (2)
Explanation
Aligning security goals with business goals (B) is the most powerful lever for shaping organizational culture because security becomes embedded in how the business thinks and operates - people adopt secure behaviors when they see security as enabling business success rather than obstructing it. An independent GRC organization (A) provides oversight and structure but operates at arm's length from the culture itself; compliance and auditing alone don't change mindsets. Compliance with local privacy regulations (C) is a legal obligation, not a cultural driver - it sets a floor, not a direction. Legal and HR support (D) is valuable for enforcement and policy, but support functions don't lead cultural change on their own. Memory tip: Think of it as "speak the language of the business" - when the CISO frames security in terms of revenue protection, customer trust, and strategic risk, executives and employees naturally internalize it, which is the essence of culture change.
Topics
Community Discussion
No community discussion yet for this question.