nerdexam
Isaca

CISM · Question #40

Which of the following should be the PRIMARY goal of information security?

The correct answer is A. Business alignment. The primary goal of information security is to align with and support business objectives, enabling the organization to achieve its mission securely.

Submitted by katya_ua· Apr 18, 2026Information Security Governance

Question

Which of the following should be the PRIMARY goal of information security?

Options

  • ABusiness alignment
  • BRegulatory compliance
  • CData governance
  • DInformation management

How the community answered

(23 responses)
  • A
    91% (21)
  • B
    4% (1)
  • C
    4% (1)

Why each option

The primary goal of information security is to align with and support business objectives, enabling the organization to achieve its mission securely.

ABusiness alignmentCorrect

Information security's ultimate purpose is to support and enable the business functions and objectives by protecting its information assets, rather than existing as an isolated function. Security measures must align with business needs to be effective and relevant.

BRegulatory compliance

Regulatory compliance is a critical requirement but is a means to an end, often driven by business needs, not the overarching primary goal itself.

CData governance

Data governance is a component of information management and security, focusing on data policies and controls, but not the primary goal of the entire information security program.

DInformation management

Information management is a broader discipline that encompasses how information is acquired, organized, stored, and retrieved; information security is a crucial part of it, but not the primary goal of security itself.

Concept tested: Information security strategic goals

Source: https://www.isaca.org/resources/isaca-journal/issues/2014/volume-6/integrating-information-security-and-business-strategy

Topics

#Information security objectives#Business alignment#Strategic importance

Community Discussion

No community discussion yet for this question.

Full CISM Practice