nerdexam
Isaca

CISM · Question #104

Which of the following is MOST likely to improve an organization's security culture?

The correct answer is A. Involving stakeholders in security planning. Involving stakeholders in security planning actively engages them, fosters a sense of ownership, and significantly improves the organization's security culture.

Submitted by parkjh· Apr 18, 2026Information Security Governance

Question

Which of the following is MOST likely to improve an organization's security culture?

Options

  • AInvolving stakeholders in security planning
  • BEnforcing penalties for security incidents
  • CCommunicating security incidents within the industry
  • DIncentivizing managers based on security metrics

How the community answered

(22 responses)
  • A
    82% (18)
  • C
    5% (1)
  • D
    14% (3)

Why each option

Involving stakeholders in security planning actively engages them, fosters a sense of ownership, and significantly improves the organization's security culture.

AInvolving stakeholders in security planningCorrect

Involving stakeholders in security planning fosters a sense of ownership and shared responsibility, making security a collective effort rather than solely an IT department concern. This engagement ensures that security measures are practical, understood, and supported across various departments, leading to a more robust and pervasive security culture.

BEnforcing penalties for security incidents

Enforcing penalties, while necessary for compliance, can foster resentment and fear, which are detrimental to building a positive and proactive security culture.

CCommunicating security incidents within the industry

Communicating security incidents within the industry can raise external awareness but does not directly translate to improved internal security culture among employees.

DIncentivizing managers based on security metrics

Incentivizing managers based on security metrics can drive performance but might also lead to "gaming" metrics rather than genuinely improving the security culture if not carefully implemented.

Concept tested: Cultivating security culture

Topics

#Security Culture#Stakeholder Engagement#Security Planning#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice