nerdexam
Isaca

CISM · Question #543

Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?

The correct answer is D. Identification of business-specific risk factors. Identifying business-specific risk factors ensures the security program is built around the organization’s unique strategic priorities and challenges, directly aligning security efforts with the overall business strategy.

Submitted by miguelv· Apr 18, 2026Information Security Governance

Question

Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?

Options

  • ABenchmarking against industry peers
  • BAdoption of an industry recognized framework
  • CApproval from senior management
  • DIdentification of business-specific risk factors

How the community answered

(58 responses)
  • A
    7% (4)
  • B
    5% (3)
  • C
    14% (8)
  • D
    74% (43)

Explanation

Identifying business-specific risk factors ensures the security program is built around the organization’s unique strategic priorities and challenges, directly aligning security efforts with the overall business strategy.

Topics

#Program Alignment#Organizational Strategy#Business Risk#Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice