nerdexam
Isaca

CISM · Question #916

Which of the following is MOST crucial to the success of an information security program?

The correct answer is C. Integration with existing business processes. An information security program that operates in isolation from business processes will be ignored, worked around, or seen as an obstacle. Integration with existing business processes means security becomes embedded in how work actually gets done - in procurement, development…

Submitted by rohit_dlh· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST crucial to the success of an information security program?

Options

  • AAlignment with globally recognized frameworks
  • BAdherence to applicable regulations
  • CIntegration with existing business processes
  • DPolicy approval by the steering committee

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    17% (8)
  • C
    72% (34)
  • D
    4% (2)

Explanation

An information security program that operates in isolation from business processes will be ignored, worked around, or seen as an obstacle. Integration with existing business processes means security becomes embedded in how work actually gets done - in procurement, development, HR onboarding, change management, and more. This is what makes security sustainable and effective. Framework alignment (A) and regulatory adherence (B) are important constraints, and steering committee approval (D) provides governance, but none of these ensure the program is actually adopted and effective in practice.

Topics

#Information security program success#Business process integration#Program effectiveness#Security culture

Community Discussion

No community discussion yet for this question.

Full CISM Practice