nerdexam
Isaca

CISM · Question #836

What should be the information security manager's FIRST step when updating an information security program?

The correct answer is A. Re-evaluate the organization's business expectations and objectives. Updating an information security program should begin by re-evaluating the organization’s business expectations and objectives, because the program must be aligned to current business direction before identifying misaligned components, benchmarking costs, or interviewing

Submitted by fatima_kr· Apr 18, 2026Information Security Program Development and Management

Question

What should be the information security manager's FIRST step when updating an information security program?

Options

  • ARe-evaluate the organization's business expectations and objectives.
  • BIdentity program components that do not align with business objectives.
  • CReview costs and benchmark them against industry norms.
  • DInterview business unit managers and key stakeholders.

How the community answered

(40 responses)
  • A
    70% (28)
  • B
    20% (8)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Updating an information security program should begin by re-evaluating the organization’s business expectations and objectives, because the program must be aligned to current business direction before identifying misaligned components, benchmarking costs, or interviewing

Topics

#Information Security Program Management#Business Alignment#Strategic Planning#Program Lifecycle

Community Discussion

No community discussion yet for this question.

Full CISM Practice