nerdexam
Isaca

CISM · Question #422

Which of the following is MOST important for obtaining senior management commitment for an updated information security strategy following the identification of new risk?

The correct answer is B. Demonstrating the impact to the organization. To obtain senior management commitment for an updated information security strategy, it is crucial to demonstrate the impact that newly identified risks pose to the organization. Senior management prioritizes decisions based on business impact, so clearly showing how these risks

Submitted by suresh_in· Apr 18, 2026Information Security Governance

Question

Which of the following is MOST important for obtaining senior management commitment for an updated information security strategy following the identification of new risk?

Options

  • ACapturing the risk in the risk register
  • BDemonstrating the impact to the organization
  • CUpdating the risk assessment process
  • DPresenting a list of recent incidents in the industry

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    75% (15)
  • C
    5% (1)
  • D
    5% (1)

Explanation

To obtain senior management commitment for an updated information security strategy, it is crucial to demonstrate the impact that newly identified risks pose to the organization. Senior management prioritizes decisions based on business impact, so clearly showing how these risks affect financials, operations, reputation, or compliance will justify the need for strategic updates. While capturing risks in a register and updating risk assessments are important, they do not directly drive executive-level commitment as effectively as demonstrating impact.

Topics

#Senior Management Commitment#Risk Communication#Business Impact Analysis#Information Security Strategy

Community Discussion

No community discussion yet for this question.

Full CISM Practice