nerdexam
Isaca

CISM · Question #807

Which of the following should be the PRIMARY objective when establishing a new information security program?

The correct answer is C. Managing organizational risk. The primary objective of an information security program is to manage organizational risk by protecting information assets in alignment with business objectives. Compliance, resource optimization, and operational security are important outcomes, but they are secondary to…

Submitted by deeparc· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should be the PRIMARY objective when establishing a new information security program?

Options

  • AOptimizing resources
  • BMeeting compliance requirements
  • CManaging organizational risk
  • DFacilitating operational security

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    88% (29)
  • D
    6% (2)

Explanation

The primary objective of an information security program is to manage organizational risk by protecting information assets in alignment with business objectives. Compliance, resource optimization, and operational security are important outcomes, but they are secondary to effective risk management.

Topics

#Information security program objectives#Risk management#Program establishment#Security strategy

Community Discussion

No community discussion yet for this question.

Full CISM Practice