CISM · Question #251
Business objectives and organizational risk appetite are MOST useful inputs to the development of information security:
The correct answer is A. strategy. Information security strategy defines the long-term direction of the security program and must be built on the organization's business objectives (to ensure alignment and relevance) and risk appetite (to ensure that security investments match the organization's acceptable risk…
Question
Business objectives and organizational risk appetite are MOST useful inputs to the development of information security:
Options
- Astrategy.
- Brisk assessments.
- Ckey performance indicators (KPIs).
- Dstandards.
How the community answered
(48 responses)- A92% (44)
- B2% (1)
- C2% (1)
- D4% (2)
Explanation
Information security strategy defines the long-term direction of the security program and must be built on the organization's business objectives (to ensure alignment and relevance) and risk appetite (to ensure that security investments match the organization's acceptable risk threshold). Risk assessments (B) are operational exercises, not strategy documents. KPIs (C) measure execution against a strategy that already exists. Standards (D) are technical controls that implement strategy. Business objectives and risk appetite are strategic-level inputs, making strategy the most appropriate output to associate with them.
Topics
Community Discussion
No community discussion yet for this question.