nerdexam
Isaca

CISM · Question #496

An organization's head of information security has been tasked with creating an information security strategy. What is the MOST important reason to include organization-wide representation?

The correct answer is A. To ensure business goals are considered. Including organization-wide representation ensures that the security strategy aligns with and supports the actual goals of the business - security exists to enable the organization, not operate in isolation, so input from all departments prevents a strategy that protects assets…

Submitted by andres_qro· Apr 18, 2026Information Security Governance

Question

An organization's head of information security has been tasked with creating an information security strategy. What is the MOST important reason to include organization-wide representation?

Options

  • ATo ensure business goals are considered
  • BTo provide guidance on data classification
  • CTo determine the appropriate business risk appetite
  • DTo establish an enterprise security architecture

How the community answered

(33 responses)
  • A
    88% (29)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Including organization-wide representation ensures that the security strategy aligns with and supports the actual goals of the business - security exists to enable the organization, not operate in isolation, so input from all departments prevents a strategy that protects assets in ways that impede operations or miss critical business priorities.

Why the distractors are wrong:

  • B (data classification): Data classification is a tactical output of security work, not a reason to involve the whole organization in strategy creation.
  • C (risk appetite): Risk appetite is typically set by executive leadership and the board, not determined through broad organization-wide representation.
  • D (enterprise security architecture): Architecture is a technical implementation concern - it flows from the strategy rather than being a reason to build it collaboratively.

Memory tip: Think of the acronym BISA - Business goals come In Security strategy Always. Security strategy without business alignment is just a technical exercise; the whole point of cross-functional representation is to anchor security to what the organization actually exists to do.

Topics

#Information Security Strategy#Business Alignment#Stakeholder Engagement#Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice