CISM · Question #236
Which of the following provides the BEST evidence that the information security program is aligned to the business strategy?
The correct answer is A. Information security initiatives are directly correlated to business processes.. Alignment means security activities exist to support and enable the business - not the other way around. When security initiatives can be traced directly to specific business processes (e.g., securing a payment workflow, protecting customer data in a revenue-generating applicatio
Question
Which of the following provides the BEST evidence that the information security program is aligned to the business strategy?
Options
- AInformation security initiatives are directly correlated to business processes.
- BThe information security program requires well-defined risk tolerance.
- CThe information security program meets the chief information security officer's (CISO)
- DThe information security team is able to provide key performance indicators (KPIs) to senior
How the community answered
(38 responses)- A79% (30)
- B3% (1)
- C11% (4)
- D8% (3)
Explanation
Alignment means security activities exist to support and enable the business - not the other way around. When security initiatives can be traced directly to specific business processes (e.g., securing a payment workflow, protecting customer data in a revenue-generating application), it demonstrates that security priorities were derived from business priorities. This traceability is concrete evidence of alignment. Risk tolerance is a governance input, not evidence of alignment. Meeting the CISO's requirements reflects internal security standards, not business alignment. KPIs measure performance and efficiency, but high KPIs do not prove the program is working on the right things from a business perspective.
Topics
Community Discussion
No community discussion yet for this question.