CISM · Question #776
Which of the following should be the MOST important consideration when reviewing an information security strategy?
The correct answer is B. New business initiatives. New business initiatives (B) should drive the most important consideration because an information security strategy exists to enable and protect the business - if new initiatives (expansions, products, acquisitions, digital transformations) aren't reflected in the strategy, it…
Question
Which of the following should be the MOST important consideration when reviewing an information security strategy?
Options
- ARecent security incidents
- BNew business initiatives
- CIndustry security standards
- DInternal audit findings
How the community answered
(17 responses)- A6% (1)
- B76% (13)
- C12% (2)
- D6% (1)
Explanation
New business initiatives (B) should drive the most important consideration because an information security strategy exists to enable and protect the business - if new initiatives (expansions, products, acquisitions, digital transformations) aren't reflected in the strategy, it becomes misaligned with what the organization actually needs to protect.
Why the distractors fall short:
- A (Recent security incidents) - incidents are reactive inputs; they may refine controls but shouldn't dictate overall strategic direction.
- C (Industry security standards) - standards like ISO 27001 or NIST provide a useful baseline, but they're generic and don't account for your organization's specific business context or risk appetite.
- D (Internal audit findings) - audit findings address compliance gaps and past failures; valuable operationally, but again reactive and tactical rather than strategic.
Memory tip: Think of security strategy as a servant of the business. Ask "what is the business trying to do next?" - that question always outranks "what went wrong before?" when setting strategic direction. On CISM/CISSP-style exams, business alignment answers almost always beat compliance or incident-response answers at the strategy level.
Topics
Community Discussion
No community discussion yet for this question.