nerdexam
Isaca

CISM · Question #269

Which of the following is the BEST indication of a mature information security program?

The correct answer is B. Information security functions are integrated throughout the business.. A mature information security program is one where security functions are embedded and integrated throughout all business operations - not siloed within an IT or security department. This integration means security is considered in HR processes, procurement, product development,

Submitted by anjalisingh· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the BEST indication of a mature information security program?

Options

  • AThe information security program is approved by business owners.
  • BInformation security functions are integrated throughout the business.
  • CInformation security is part of the application development process.
  • DSenior management is supportive of the information security program.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    79% (19)
  • C
    13% (3)
  • D
    4% (1)

Explanation

A mature information security program is one where security functions are embedded and integrated throughout all business operations - not siloed within an IT or security department. This integration means security is considered in HR processes, procurement, product development, operations, and finance, reflecting a security-aware organizational culture. Option A (business owner approval) and Option D (senior management support) are necessary conditions for any program but indicate sponsorship, not maturity. Option C (security in application development) is one dimension of integration but is too narrow to characterize overall program maturity. Pervasive integration across the entire business is the defining characteristic that separates a mature program from one that merely exists.

Topics

#Information security program maturity#Security program integration#Security program management#Business alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice