CISM · Question #285
Which of the following is the MOST important aspect for an information security manager to consider when developing effective information security policies?
The correct answer is D. Policies should be aligned with the business. Aligning policies with the business is the foundational requirement because security policies exist to protect business objectives - if policies don't reflect what the organization actually does, its risk appetite, and its operational needs, they become irrelevant or actively obs
Question
Which of the following is the MOST important aspect for an information security manager to consider when developing effective information security policies?
Options
- ASenior management should agree with the policies
- BPolicies should be updated when new technologies are introduced
- CPersonnel should be trained on security policies
- DPolicies should be aligned with the business
How the community answered
(57 responses)- A2% (1)
- B4% (2)
- C7% (4)
- D88% (50)
Explanation
Aligning policies with the business is the foundational requirement because security policies exist to protect business objectives - if policies don't reflect what the organization actually does, its risk appetite, and its operational needs, they become irrelevant or actively obstructive, no matter how technically sound they are.
Why the distractors fall short:
- A (Senior management agreement): Management buy-in is essential for enforcement, but agreement without alignment to business goals produces policies that are approved yet ineffective in practice.
- B (Updated for new technologies): Keeping policies current matters, but it's reactive; policies driven purely by technology trends rather than business direction lose strategic coherence.
- C (Personnel training): Training ensures policies are followed, but you can perfectly train staff on policies that don't serve the business - training amplifies policy quality, it doesn't substitute for it.
Memory tip: Think of security policy as a service to the business, not a constraint on it. On the exam, when a question asks about the most important or primary consideration for security governance, answers tied to business alignment, objectives, or strategy almost always outrank answers about implementation steps (training, updates) or stakeholder dynamics (management approval).
Topics
Community Discussion
No community discussion yet for this question.