nerdexam
Isaca

CISM · Question #202

An organization has updated its business goals in the middle of the fiscal year to respond to changes in market conditions. Which of the following is MOST important for the information security manage

The correct answer is C. Information security strategy. When an organization's business goals change, the information security manager must first update the information security strategy, because the strategy defines how security will support and enable those business goals. The strategy drives everything downstream: objectives (B), p

Submitted by rania.sa· Apr 18, 2026Information Security Governance

Question

An organization has updated its business goals in the middle of the fiscal year to respond to changes in market conditions. Which of the following is MOST important for the information security manager to update in support of the new goals?

Options

  • AInformation security policy
  • BInformation security objectives
  • CInformation security strategy
  • DInformation security threat profile

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    3% (1)
  • C
    74% (28)
  • D
    8% (3)

Explanation

When an organization's business goals change, the information security manager must first update the information security strategy, because the strategy defines how security will support and enable those business goals. The strategy drives everything downstream: objectives (B), policies (A), and threat profiles (D). Updating policies or objectives without first updating the strategy means those elements won't be coherently aligned to the new direction. The strategy is the bridge between business goals and security execution.

Topics

#Security Strategy#Business Alignment#Strategic Planning#Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice