nerdexam
Isaca

CISM · Question #593

Which of the following is MOST important for the development of an information security strategy?

The correct answer is D. Evaluating information security requirements. Understanding and evaluating information security requirements is most important, as it ensures the strategy aligns with business needs, regulatory obligations, and risk posture from the outset.

Submitted by manish99· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST important for the development of an information security strategy?

Options

  • AObtaining adequate information security budget
  • BEvaluating the control environment
  • CBuilding an incident response team
  • DEvaluating information security requirements

How the community answered

(41 responses)
  • A
    10% (4)
  • B
    2% (1)
  • C
    7% (3)
  • D
    80% (33)

Explanation

Understanding and evaluating information security requirements is most important, as it ensures the strategy aligns with business needs, regulatory obligations, and risk posture from the outset.

Topics

#Information Security Strategy#Strategy Development#Security Requirements#Strategic Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice