Isaca
CISM · Question #543
Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?
The correct answer is D. Identification of business-specific risk factors. Identifying business-specific risk factors ensures the security program is built around the organization’s unique strategic priorities and challenges, directly aligning security efforts with the overall business strategy.
Submitted by miguelv· Apr 18, 2026Information Security Governance
Question
Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?
Options
- ABenchmarking against industry peers
- BAdoption of an industry recognized framework
- CApproval from senior management
- DIdentification of business-specific risk factors
How the community answered
(58 responses)- A7% (4)
- B5% (3)
- C14% (8)
- D74% (43)
Explanation
Identifying business-specific risk factors ensures the security program is built around the organization’s unique strategic priorities and challenges, directly aligning security efforts with the overall business strategy.
Topics
#Program Alignment#Organizational Strategy#Business Risk#Security Governance
Community Discussion
No community discussion yet for this question.