nerdexam
Isaca

CISM · Question #776

Which of the following should be the MOST important consideration when reviewing an information security strategy?

The correct answer is B. New business initiatives. New business initiatives (B) should drive the most important consideration because an information security strategy exists to enable and protect the business - if new initiatives (expansions, products, acquisitions, digital transformations) aren't reflected in the strategy, it…

Submitted by stefanr· Apr 18, 2026Information Security Governance

Question

Which of the following should be the MOST important consideration when reviewing an information security strategy?

Options

  • ARecent security incidents
  • BNew business initiatives
  • CIndustry security standards
  • DInternal audit findings

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    76% (13)
  • C
    12% (2)
  • D
    6% (1)

Explanation

New business initiatives (B) should drive the most important consideration because an information security strategy exists to enable and protect the business - if new initiatives (expansions, products, acquisitions, digital transformations) aren't reflected in the strategy, it becomes misaligned with what the organization actually needs to protect.

Why the distractors fall short:

  • A (Recent security incidents) - incidents are reactive inputs; they may refine controls but shouldn't dictate overall strategic direction.
  • C (Industry security standards) - standards like ISO 27001 or NIST provide a useful baseline, but they're generic and don't account for your organization's specific business context or risk appetite.
  • D (Internal audit findings) - audit findings address compliance gaps and past failures; valuable operationally, but again reactive and tactical rather than strategic.

Memory tip: Think of security strategy as a servant of the business. Ask "what is the business trying to do next?" - that question always outranks "what went wrong before?" when setting strategic direction. On CISM/CISSP-style exams, business alignment answers almost always beat compliance or incident-response answers at the strategy level.

Topics

#Information Security Strategy#Business Alignment#Strategic Review#Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice