nerdexam
Isaca

CISM · Question #150

When developing a business case for a new security initiative, an information security manager should FIRST:

The correct answer is D. define the issues to be addressed. Defining the issues to be addressed is the necessary first step because every subsequent element of a business case - feasibility, cost, benefit - depends on a clear problem statement. Without knowing what problem you are solving, you cannot assess feasibility (A), calculate…

Submitted by fatima_kr· Apr 18, 2026Information Security Program Development and Management

Question

When developing a business case for a new security initiative, an information security manager should FIRST:

Options

  • Aconduct a feasibility study.
  • Bcalculate the total cost of ownership (TCO).
  • Cperform a cost-benefit analysis.
  • Ddefine the issues to be addressed.

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (25)

Explanation

Defining the issues to be addressed is the necessary first step because every subsequent element of a business case - feasibility, cost, benefit - depends on a clear problem statement. Without knowing what problem you are solving, you cannot assess feasibility (A), calculate relevant costs (B), or perform a meaningful cost-benefit analysis (C). A well-defined problem statement also ensures alignment with business objectives and makes the case more compelling to stakeholders. This follows the fundamental principle: understand the problem before proposing a solution.

Topics

#Business Case Development#Security Program Planning#Needs Assessment#Project Initiation

Community Discussion

No community discussion yet for this question.

Full CISM Practice