nerdexam
Isaca

CISM · Question #427

Which of the following BEST indicates misalignment of security policies with business objectives?

The correct answer is D. A large number of long-term policy exceptions. A high number of long-term policy exceptions indicates that security policies are not aligned with business objectives, as users and departments are frequently unable to comply with them. This suggests that the policies may be too restrictive, impractical, or not adequately consi

Submitted by the_admin· Apr 18, 2026Information Security Governance

Question

Which of the following BEST indicates misalignment of security policies with business objectives?

Options

  • ALow completion rate of employee awareness training
  • BLack of adequate funding for the security program
  • CA large number of user noncompliance incidents
  • DA large number of long-term policy exceptions

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    29% (7)
  • C
    4% (1)
  • D
    50% (12)

Explanation

A high number of long-term policy exceptions indicates that security policies are not aligned with business objectives, as users and departments are frequently unable to comply with them. This suggests that the policies may be too restrictive, impractical, or not adequately considering business needs. While low training completion, funding issues, and user noncompliance are concerns, they do not directly reflect misalignment between security policies and business objectives as clearly as policy exceptions do.

Topics

#Security Policy#Policy Alignment#Business Objectives#Policy Exceptions

Community Discussion

No community discussion yet for this question.

Full CISM Practice