nerdexam
Isaca

CISM · Question #93

Which of the following is the MOST important success factor when developing an information security strategy?

The correct answer is D. The strategy is approved by the board and executive management. The most critical success factor for an information security strategy is gaining approval from the board and executive management, ensuring top-level support and integration.

Submitted by obi.ng· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST important success factor when developing an information security strategy?

Options

  • AThe delivery of the strategy is adequately funded.
  • BThe strategy is aligned with an industry-recognized security control framework.
  • CThe strategy is based on proven technologies and industry trends.
  • DThe strategy is approved by the board and executive management.

How the community answered

(25 responses)
  • A
    16% (4)
  • B
    4% (1)
  • C
    8% (2)
  • D
    72% (18)

Why each option

The most critical success factor for an information security strategy is gaining approval from the board and executive management, ensuring top-level support and integration.

AThe delivery of the strategy is adequately funded.

Adequate funding is crucial, but it is typically a consequence of gaining board and executive approval, making the approval itself the more fundamental factor.

BThe strategy is aligned with an industry-recognized security control framework.

Alignment with a security control framework is a best practice for strategy design, but securing executive approval is more critical for successful implementation and sustained support.

CThe strategy is based on proven technologies and industry trends.

Basing the strategy on proven technologies and trends contributes to its technical soundness but doesn't guarantee organizational adoption or resource allocation without executive approval.

DThe strategy is approved by the board and executive management.Correct

Approval by the board and executive management is the MOST important success factor because it ensures that the security strategy has the necessary top-down mandate, financial backing, and organizational priority. Without this executive buy-in, even a well-designed strategy will struggle to secure resources, gain organizational acceptance, and be effectively implemented.

Concept tested: Executive sponsorship for security strategy

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/adopting-a-security-posture

Topics

#Information Security Strategy#Executive Buy-in#Governance#Strategic Alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice