nerdexam
Isaca

CISM · Question #810

Which of the following would be the GREATEST concern if an information security manager defines a security approach according to industry best practices?

The correct answer is A. Alignment with organizational objectives. Defining a security approach solely based on industry best practices may result in misalignment with the organization’s specific business objectives and risk appetite. CISM emphasizes that security must be business-driven; best practices should be adapted, not adopted blindly.

Submitted by ricky.ec· Apr 18, 2026Information Security Governance

Question

Which of the following would be the GREATEST concern if an information security manager defines a security approach according to industry best practices?

Options

  • AAlignment with organizational objectives
  • BAlignment with IT strategy
  • CExcessive security control cost
  • DManual control framework

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    7% (2)
  • C
    4% (1)
  • D
    14% (4)

Explanation

Defining a security approach solely based on industry best practices may result in misalignment with the organization’s specific business objectives and risk appetite. CISM emphasizes that security must be business-driven; best practices should be adapted, not adopted blindly.

Topics

#Security governance#Business alignment#Organizational objectives#Strategic security

Community Discussion

No community discussion yet for this question.

Full CISM Practice