nerdexam
Isaca

CISM · Question #709

Which of the following is the PRIMARY objective of developing an information security strategy?

The correct answer is C. Moving from the current state of security to the desired state. The PRIMARY objective of an information security strategy is to serve as a roadmap that moves the organization from its current security posture to a clearly defined desired future state - aligning security capabilities with business objectives over time. This is the essence of…

Submitted by joshua94· Apr 18, 2026Information Security Governance

Question

Which of the following is the PRIMARY objective of developing an information security strategy?

Options

  • AMaintaining a structured security architecture
  • BPrioritizing security risk based on impact
  • CMoving from the current state of security to the desired state
  • DEnabling the organization to define security-related business processes

How the community answered

(15 responses)
  • A
    7% (1)
  • C
    93% (14)

Explanation

The PRIMARY objective of an information security strategy is to serve as a roadmap that moves the organization from its current security posture to a clearly defined desired future state - aligning security capabilities with business objectives over time. This is the essence of strategic planning. Option A (structured security architecture) is a component or output of strategy, not the objective itself. Option B (prioritizing risk by impact) is a tactic within risk management. Option D (defining security-related business processes) is an enabling activity, not the strategic objective.

Topics

#information security strategy#strategic planning#program direction#current-to-desired state transition

Community Discussion

No community discussion yet for this question.

Full CISM Practice