nerdexam
Isaca

CGEIT · Question #670

Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?

The correct answer is A. Refining relevant business goals. The initial consideration for a CISO implementing Zero Trust architecture should be refining relevant business goals to ensure security initiatives align with organizational objectives.

Submitted by fernanda_arg· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?

Options

  • ARefining relevant business goals.
  • BLimiting the number of privileged accounts.
  • CSelecting a security framework that is relevant to the business.
  • DDefining security projects to address identified control gaps.

How the community answered

(50 responses)
  • A
    70% (35)
  • B
    16% (8)
  • C
    6% (3)
  • D
    8% (4)

Why each option

The initial consideration for a CISO implementing Zero Trust architecture should be refining relevant business goals to ensure security initiatives align with organizational objectives.

ARefining relevant business goals.Correct

Before implementing any security architecture like Zero Trust, a CISO must first understand and refine the relevant business goals, as security should always be an enabler of the business rather than a standalone technical exercise. Aligning Zero Trust principles with specific business outcomes ensures the architecture supports organizational objectives effectively.

BLimiting the number of privileged accounts.

Limiting privileged accounts is a key component of Zero Trust but is a specific implementation step, not the foundational first consideration before strategy alignment.

CSelecting a security framework that is relevant to the business.

Selecting a security framework is important but comes after understanding the business context and goals, as the framework choice should support those objectives.

DDefining security projects to address identified control gaps.

Defining security projects and addressing control gaps are tactical steps that flow from the overall strategy, which itself is driven by business goals.

Concept tested: Aligning Zero Trust with business goals

Source: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview

Topics

#Zero Trust Architecture#CISO Responsibilities#Strategic Planning#Business Alignment

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice