nerdexam
Isaca

CISM · Question #786

What is the PRIMARY reason to involve stakeholders from various business units when developing an information security policy?

The correct answer is B. To gain acceptance of the policy across the organization. Involving stakeholders from various business units promotes buy-in, relevance, and adherence. When users feel they've had input in shaping the policy, they're more likely to support and follow it. Stakeholders also provide insights into business processes that help ensure…

Submitted by miguelv· Apr 18, 2026Information Security Governance

Question

What is the PRIMARY reason to involve stakeholders from various business units when developing an information security policy?

Options

  • ATo share responsibility for addressing security breaches
  • BTo gain acceptance of the policy across the organization
  • CTo decrease the workload of the IT department
  • DTo reduce the overall cost of policy development

How the community answered

(24 responses)
  • B
    88% (21)
  • C
    4% (1)
  • D
    8% (2)

Explanation

Involving stakeholders from various business units promotes buy-in, relevance, and adherence. When users feel they've had input in shaping the policy, they're more likely to support and follow it. Stakeholders also provide insights into business processes that help ensure policies are practical and tailored. This collaboration enhances organizational alignment and ensures policies do not create unintended operational friction. "Stakeholder involvement is key to ensuring that policies are practical, aligned with operations, and accepted throughout the organization."

Topics

#Stakeholder engagement#Security policy#Policy development#Organizational buy-in

Community Discussion

No community discussion yet for this question.

Full CISM Practice