nerdexam
Isaca

CISM · Question #917

Which of the following would be MOST useful to a newly hired information security manager who has been tasked with developing and implementing an information security strategy?

The correct answer is B. The organization's business strategy. An information security strategy must align with and support the organization's overall business objectives - without knowing where the business is headed, a security strategy has no meaningful direction or priorities. The business strategy reveals critical assets, risk…

Submitted by rania.sa· Apr 18, 2026Information Security Governance

Question

Which of the following would be MOST useful to a newly hired information security manager who has been tasked with developing and implementing an information security strategy?

Options

  • AThe capabilities of the information security team
  • BThe organization's business strategy
  • CA prior information security strategy
  • DThe organization's IT strategy

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    71% (24)
  • C
    15% (5)
  • D
    9% (3)

Explanation

An information security strategy must align with and support the organization's overall business objectives - without knowing where the business is headed, a security strategy has no meaningful direction or priorities. The business strategy reveals critical assets, risk tolerance, regulatory environment, and growth plans that determine what must be protected and why. Team capabilities (A) are a resource constraint to consider later. A prior security strategy (C) may be outdated or misaligned. The IT strategy (D) is only one component of the broader business strategy and is itself derived from it.

Topics

#Information Security Strategy#Business Alignment#Strategic Planning#Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice