CISM · Question #737
Which of the following is the MOST critical input to developing policies, standards, and procedures to secure information assets?
The correct answer is C. Enterprise goals. Enterprise goals (C) are the most critical input because security policies exist to protect the organization's ability to achieve its objectives - if policies don't align with what the business is trying to accomplish, they will either be ignored or actively obstruct operations,
Question
Which of the following is the MOST critical input to developing policies, standards, and procedures to secure information assets?
Options
- AVulnerability assessment
- BRegulatory requirements
- CEnterprise goals
- DIndustry best practices
How the community answered
(55 responses)- A7% (4)
- B2% (1)
- C87% (48)
- D4% (2)
Explanation
Enterprise goals (C) are the most critical input because security policies exist to protect the organization's ability to achieve its objectives - if policies don't align with what the business is trying to accomplish, they will either be ignored or actively obstruct operations, making them ineffective regardless of how technically sound they are.
Why the distractors fall short:
- A (Vulnerability assessment) identifies current weaknesses but is tactical and point-in-time; it informs controls, not the foundational direction of policy.
- B (Regulatory requirements) are external constraints that set a floor, not a ceiling - they're inputs you must satisfy, but they don't define what the organization is trying to protect or why.
- D (Industry best practices) are generic starting points borrowed from peers; they aren't tailored to what your organization values or is trying to achieve.
Memory tip: Think of it as "policy must serve purpose." Regulations, best practices, and vulnerability data all feed into policy design, but without knowing the enterprise's goals, you have no way to prioritize or scope any of them - goals are the lens through which everything else is evaluated.
Topics
Community Discussion
No community discussion yet for this question.