nerdexam
Isaca

CISM · Question #622

What is the PRIMARY role of the information security program?

The correct answer is B. To provide guidance in managing organizational security risk. The overarching purpose of an information security program is to provide a framework and guidance for managing organizational security risk in alignment with business objectives. All other activities - approving requirements (A), educating stakeholders (C), and conducting risk…

Submitted by carter_n· Apr 18, 2026Information Security Program

Question

What is the PRIMARY role of the information security program?

Options

  • ATo approve information security requirements related to the business
  • BTo provide guidance in managing organizational security risk
  • CTo educate stakeholders regarding information security requirements
  • DTo perform periodic risk assessments and business impact analyses (BIAs)

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    88% (30)
  • C
    3% (1)
  • D
    3% (1)

Explanation

The overarching purpose of an information security program is to provide a framework and guidance for managing organizational security risk in alignment with business objectives. All other activities - approving requirements (A), educating stakeholders (C), and conducting risk assessments and BIAs (D) - are supporting functions that serve this primary goal. The program exists to ensure the organization understands and manages its security risks in a structured, consistent way.

Topics

#Information Security Program#Risk Management#Organizational Security#Program Objectives

Community Discussion

No community discussion yet for this question.

Full CISM Practice