nerdexam
Isaca

CISM · Question #68

Which of the following should be the PRIMARY objective for creating a culture of security within an organization?

The correct answer is B. To reduce risk to acceptable levels. The primary objective for creating a culture of security within an organization is to reduce overall risk to acceptable levels.

Submitted by chen.hong· Apr 18, 2026Information Security Risk Management

Question

Which of the following should be the PRIMARY objective for creating a culture of security within an organization?

Options

  • ATo obtain resources for information security initiatives
  • BTo reduce risk to acceptable levels
  • CTo prioritize security within the organization
  • DTo demonstrate control effectiveness to senior management

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    94% (32)
  • D
    3% (1)

Why each option

The primary objective for creating a culture of security within an organization is to reduce overall risk to acceptable levels.

ATo obtain resources for information security initiatives

Obtaining resources for information security initiatives is a means to achieve security goals, not the primary objective of a security culture itself.

BTo reduce risk to acceptable levelsCorrect

The primary objective for creating a culture of security is to reduce overall organizational risk to acceptable levels by integrating security awareness and practices into the daily routines and mindset of all employees. This collective responsibility and vigilance help prevent incidents stemming from human error or malicious intent, thereby mitigating potential threats and vulnerabilities effectively.

CTo prioritize security within the organization

To prioritize security within the organization is an outcome of a strong security culture, but the ultimate goal of that prioritization is the reduction of risk.

DTo demonstrate control effectiveness to senior management

Demonstrating control effectiveness to senior management is a management function that might be aided by a strong security culture, but it's not the culture's primary objective.

Concept tested: Security culture objectives

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf

Topics

#Security Culture#Risk Reduction#Information Security Objectives#Security Program

Community Discussion

No community discussion yet for this question.

Full CISM Practice