nerdexam
Isaca

CISM · Question #132

Which of the following is MOST important to include in an enterprise information security policy?

The correct answer is B. Security objectives. Security objectives establish the purpose and strategic direction of the entire information security program. They define what the organization intends to achieve and provide the foundation from which all other policy elements, procedures, and controls are derived. Without object

Submitted by viktor_hu· Apr 18, 2026Information Security Governance

Question

Which of the following is MOST important to include in an enterprise information security policy?

Options

  • AAcceptable use
  • BSecurity objectives
  • CSecurity metrics
  • DAudit trail review requirements

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    88% (29)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Security objectives establish the purpose and strategic direction of the entire information security program. They define what the organization intends to achieve and provide the foundation from which all other policy elements, procedures, and controls are derived. Without objectives, a policy lacks meaning and measurability. Acceptable use (A) is an operational directive. Security metrics (C) measure progress toward objectives-they cannot exist without first having objectives defined. Audit trail review requirements (D) are a procedural control that stems from objectives around accountability and monitoring.

Topics

#Information Security Policy#Security Objectives#Policy Development#Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice