nerdexam
Isaca

CISM · Question #251

Business objectives and organizational risk appetite are MOST useful inputs to the development of information security:

The correct answer is A. strategy. Information security strategy defines the long-term direction of the security program and must be built on the organization's business objectives (to ensure alignment and relevance) and risk appetite (to ensure that security investments match the organization's acceptable risk…

Submitted by satoshi_tk· Apr 18, 2026Information Security Governance

Question

Business objectives and organizational risk appetite are MOST useful inputs to the development of information security:

Options

  • Astrategy.
  • Brisk assessments.
  • Ckey performance indicators (KPIs).
  • Dstandards.

How the community answered

(48 responses)
  • A
    92% (44)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Information security strategy defines the long-term direction of the security program and must be built on the organization's business objectives (to ensure alignment and relevance) and risk appetite (to ensure that security investments match the organization's acceptable risk threshold). Risk assessments (B) are operational exercises, not strategy documents. KPIs (C) measure execution against a strategy that already exists. Standards (D) are technical controls that implement strategy. Business objectives and risk appetite are strategic-level inputs, making strategy the most appropriate output to associate with them.

Topics

#Information security strategy#Business alignment#Risk appetite#Security governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice