nerdexam
Isaca

CISM · Question #851

Which of the following should be the PRIMARY basis for determining information security objectives?

The correct answer is D. Business strategy. Information security exists to protect and enable the business - therefore security objectives must flow from and align with business strategy (D). Security that is not grounded in business goals risks being misaligned, over-scoped, or irrelevant to what the organization is actua

Submitted by the_admin· Apr 18, 2026Information Security Governance

Question

Which of the following should be the PRIMARY basis for determining information security objectives?

Options

  • AAsset inventory
  • BRegulatory requirements
  • CInformation security strategy
  • DBusiness strategy

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    93% (27)

Explanation

Information security exists to protect and enable the business - therefore security objectives must flow from and align with business strategy (D). Security that is not grounded in business goals risks being misaligned, over-scoped, or irrelevant to what the organization is actually trying to achieve. Regulatory requirements (B) are important constraints but are minimum compliance thresholds, not strategic drivers. An asset inventory (A) is an input to risk assessment, not a strategic basis. The information security strategy (C) is itself derived from business strategy - it cannot be its own primary basis without circularity. Business strategy is the authoritative source that all security objectives should trace back to.

Topics

#Information Security Objectives#Business Alignment#Strategic Planning#Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice