CISM · Question #851
Which of the following should be the PRIMARY basis for determining information security objectives?
The correct answer is D. Business strategy. Information security exists to protect and enable the business - therefore security objectives must flow from and align with business strategy (D). Security that is not grounded in business goals risks being misaligned, over-scoped, or irrelevant to what the organization is actua
Question
Which of the following should be the PRIMARY basis for determining information security objectives?
Options
- AAsset inventory
- BRegulatory requirements
- CInformation security strategy
- DBusiness strategy
How the community answered
(29 responses)- A3% (1)
- C3% (1)
- D93% (27)
Explanation
Information security exists to protect and enable the business - therefore security objectives must flow from and align with business strategy (D). Security that is not grounded in business goals risks being misaligned, over-scoped, or irrelevant to what the organization is actually trying to achieve. Regulatory requirements (B) are important constraints but are minimum compliance thresholds, not strategic drivers. An asset inventory (A) is an input to risk assessment, not a strategic basis. The information security strategy (C) is itself derived from business strategy - it cannot be its own primary basis without circularity. Business strategy is the authoritative source that all security objectives should trace back to.
Topics
Community Discussion
No community discussion yet for this question.