CISM · Question #496
An organization's head of information security has been tasked with creating an information security strategy. What is the MOST important reason to include organization-wide representation?
The correct answer is A. To ensure business goals are considered. Including organization-wide representation ensures that the security strategy aligns with and supports the actual goals of the business - security exists to enable the organization, not operate in isolation, so input from all departments prevents a strategy that protects assets…
Question
An organization's head of information security has been tasked with creating an information security strategy. What is the MOST important reason to include organization-wide representation?
Options
- ATo ensure business goals are considered
- BTo provide guidance on data classification
- CTo determine the appropriate business risk appetite
- DTo establish an enterprise security architecture
How the community answered
(33 responses)- A88% (29)
- B6% (2)
- C3% (1)
- D3% (1)
Explanation
Including organization-wide representation ensures that the security strategy aligns with and supports the actual goals of the business - security exists to enable the organization, not operate in isolation, so input from all departments prevents a strategy that protects assets in ways that impede operations or miss critical business priorities.
Why the distractors are wrong:
- B (data classification): Data classification is a tactical output of security work, not a reason to involve the whole organization in strategy creation.
- C (risk appetite): Risk appetite is typically set by executive leadership and the board, not determined through broad organization-wide representation.
- D (enterprise security architecture): Architecture is a technical implementation concern - it flows from the strategy rather than being a reason to build it collaboratively.
Memory tip: Think of the acronym BISA - Business goals come In Security strategy Always. Security strategy without business alignment is just a technical exercise; the whole point of cross-functional representation is to anchor security to what the organization actually exists to do.
Topics
Community Discussion
No community discussion yet for this question.