nerdexam
Isaca

CISM · Question #201

Which of the following is the MOST important reason to ensure information security is aligned with the organization's strategy?

The correct answer is B. To optimize security risk management. Aligning information security with organizational strategy is most importantly about optimizing security risk management (B) because strategy defines where the organization is headed, what assets matter most, and what level of risk is acceptable - security must protect those prio

Submitted by anna_se· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST important reason to ensure information security is aligned with the organization's strategy?

Options

  • ATo align security roles and responsibilities
  • BTo optimize security risk management
  • CTo identity the organization's risk tolerance
  • DTo improve security processes

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    90% (27)
  • D
    3% (1)

Explanation

Aligning information security with organizational strategy is most importantly about optimizing security risk management (B) because strategy defines where the organization is headed, what assets matter most, and what level of risk is acceptable - security must protect those priorities efficiently, allocating limited resources where they create the greatest business value.

Why the distractors fall short:

  • A (align roles/responsibilities) - a structural outcome of alignment, not its primary purpose; org charts serve the strategy, not the other way around.
  • C (identify risk tolerance) - risk tolerance is an input that informs strategy, not a result of aligning security to it; the organization defines tolerance first, then security aligns accordingly.
  • D (improve security processes) - process improvement is a byproduct of good alignment, but processes without strategic context can be optimized in the wrong direction entirely.

Memory tip: Think of it as why does a bodyguard need to know your schedule? - not to know your job title (A), not to learn your fears (C), not to practice better footwork (D), but to protect the right things at the right time with the right resources (B). That's risk management optimization.

Topics

#Information Security Governance#Strategic Alignment#Risk Management Optimization#Business Objectives

Community Discussion

No community discussion yet for this question.

Full CISM Practice