CISM · Question #40
Which of the following should be the PRIMARY goal of information security?
The correct answer is A. Business alignment. The primary goal of information security is to align with and support business objectives, enabling the organization to achieve its mission securely.
Question
Which of the following should be the PRIMARY goal of information security?
Options
- ABusiness alignment
- BRegulatory compliance
- CData governance
- DInformation management
How the community answered
(23 responses)- A91% (21)
- B4% (1)
- C4% (1)
Why each option
The primary goal of information security is to align with and support business objectives, enabling the organization to achieve its mission securely.
Information security's ultimate purpose is to support and enable the business functions and objectives by protecting its information assets, rather than existing as an isolated function. Security measures must align with business needs to be effective and relevant.
Regulatory compliance is a critical requirement but is a means to an end, often driven by business needs, not the overarching primary goal itself.
Data governance is a component of information management and security, focusing on data policies and controls, but not the primary goal of the entire information security program.
Information management is a broader discipline that encompasses how information is acquired, organized, stored, and retrieved; information security is a crucial part of it, but not the primary goal of security itself.
Concept tested: Information security strategic goals
Source: https://www.isaca.org/resources/isaca-journal/issues/2014/volume-6/integrating-information-security-and-business-strategy
Topics
Community Discussion
No community discussion yet for this question.