Isaca
CISM · Question #666
Which of the following is MOST important for an information security manager to consider when developing an information security strategy?
The correct answer is A. Organizational objectives and risk appetite. Aligning the information security strategy with organizational objectives and risk appetite ensures that security efforts support business goals while staying within acceptable levels of risk.
Submitted by jian89· Apr 18, 2026Information Security Governance
Question
Which of the following is MOST important for an information security manager to consider when developing an information security strategy?
Options
- AOrganizational objectives and risk appetite
- BThe organization's network and infrastructure
- CRoles and responsibilities of key stakeholders
- DRegulatory constraints within the organization's jurisdiction
How the community answered
(35 responses)- A86% (30)
- B9% (3)
- C3% (1)
- D3% (1)
Explanation
Aligning the information security strategy with organizational objectives and risk appetite ensures that security efforts support business goals while staying within acceptable levels of risk.
Topics
#Information security strategy#Organizational objectives#Risk appetite#Security governance
Community Discussion
No community discussion yet for this question.