nerdexam
Isaca

CISM · Question #47

Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?

The correct answer is C. Information security steering committee. An information security steering committee provides the most relevant input for aligning the information security strategy with overall organizational goals.

Submitted by suresh_in· Apr 18, 2026Information Security Governance

Question

Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?

Options

  • AData privacy officer (DPO)
  • BChief information security officer (CISO)
  • CInformation security steering committee
  • DEnterprise risk committee

How the community answered

(43 responses)
  • A
    12% (5)
  • B
    5% (2)
  • C
    81% (35)
  • D
    2% (1)

Why each option

An information security steering committee provides the most relevant input for aligning the information security strategy with overall organizational goals.

AData privacy officer (DPO)

A Data Privacy Officer (DPO) focuses specifically on privacy regulations and compliance, which is a subset of information security, and would not have the broad organizational view needed for strategic alignment.

BChief information security officer (CISO)

The Chief Information Security Officer (CISO) leads the security function, but requires input from across the organization, typically facilitated by a steering committee, to ensure the security strategy aligns with all business objectives.

CInformation security steering committeeCorrect

An information security steering committee typically comprises senior leaders from various business units, IT, and security, ensuring diverse perspectives and comprehensive understanding of organizational goals, risks, and resource allocation. This collective input is crucial for developing a security strategy that is effectively aligned with and supports the broader business objectives.

DEnterprise risk committee

An enterprise risk committee provides input on overall organizational risks, but an information security steering committee is specifically chartered to align the security strategy with business goals, making its input more directly relevant.

Concept tested: Information security governance

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-governance

Topics

#Information Security Governance#Strategic Alignment#Steering Committees#Organizational Roles and Responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice