nerdexam
Isaca

CISM · Question #61

An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?

The correct answer is C. Assess the business objectives of the processes.. The first step to integrate information security into HR processes is to assess the business objectives of those processes to ensure security measures align with and support them.

Submitted by jaden.t· Apr 18, 2026Information Security Governance

Question

An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?

Options

  • ACalculate the return on investment (ROI).
  • BProvide security awareness training to HR.
  • CAssess the business objectives of the processes.
  • DBenchmark the processes with best practice to identify gaps.

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    82% (37)
  • D
    11% (5)

Why each option

The first step to integrate information security into HR processes is to assess the business objectives of those processes to ensure security measures align with and support them.

ACalculate the return on investment (ROI).

Calculating ROI is a financial justification step that comes after understanding the needs and potential solutions, not the initial step.

BProvide security awareness training to HR.

Security awareness training is crucial but is a control implementation step that comes after understanding the risks and appropriate integration points within the processes.

CAssess the business objectives of the processes.Correct

The first step should be to assess the business objectives of the HR management processes. Understanding the goals and functions of each HR process (e.g., onboarding, offboarding, performance management) allows for the identification of critical information, potential risks, and the most effective points for integrating security controls that support, rather than hinder, the HR objectives.

DBenchmark the processes with best practice to identify gaps.

Benchmarking against best practices helps identify gaps but should follow an initial understanding of the organization's *own* processes and objectives, otherwise the comparison may not be relevant.

Concept tested: Integrating security into business processes

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/strategy/business-outcomes/

Topics

#Security integration#HR processes security#Business objectives#Strategic alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice