CISM · Question #709
Which of the following is the PRIMARY objective of developing an information security strategy?
The correct answer is C. Moving from the current state of security to the desired state. The PRIMARY objective of an information security strategy is to serve as a roadmap that moves the organization from its current security posture to a clearly defined desired future state - aligning security capabilities with business objectives over time. This is the essence of…
Question
Which of the following is the PRIMARY objective of developing an information security strategy?
Options
- AMaintaining a structured security architecture
- BPrioritizing security risk based on impact
- CMoving from the current state of security to the desired state
- DEnabling the organization to define security-related business processes
How the community answered
(15 responses)- A7% (1)
- C93% (14)
Explanation
The PRIMARY objective of an information security strategy is to serve as a roadmap that moves the organization from its current security posture to a clearly defined desired future state - aligning security capabilities with business objectives over time. This is the essence of strategic planning. Option A (structured security architecture) is a component or output of strategy, not the objective itself. Option B (prioritizing risk by impact) is a tactic within risk management. Option D (defining security-related business processes) is an enabling activity, not the strategic objective.
Topics
Community Discussion
No community discussion yet for this question.