nerdexam
Isaca

CISM · Question #99

Which of the following is the MOST important goal of an information security program?

The correct answer is B. Reducing risk factors. The primary goal of an information security program is to reduce risk factors to an acceptable level by protecting information assets from threats and vulnerabilities.

Submitted by luis.pe· Apr 18, 2026Information Security Program

Question

Which of the following is the MOST important goal of an information security program?

Options

  • AOptimizing resources
  • BReducing risk factors
  • CManaging controls
  • DEnhancing business decision making

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    87% (26)
  • C
    7% (2)
  • D
    3% (1)

Why each option

The primary goal of an information security program is to reduce risk factors to an acceptable level by protecting information assets from threats and vulnerabilities.

AOptimizing resources

Optimizing resources is a goal of efficient management but secondary to the core objective of protecting information assets through risk reduction.

BReducing risk factorsCorrect

The most important goal of an information security program is to reduce risk factors by implementing controls that mitigate threats and vulnerabilities to an acceptable level. This focus ensures the protection of an organization's information assets and supports business objectives by minimizing potential harm from security incidents. All other security activities ultimately serve this overarching objective of risk reduction.

CManaging controls

Managing controls is a means to achieve security, not the ultimate goal itself; controls are implemented to reduce risk.

DEnhancing business decision making

Enhancing business decision making can be a benefit of a well-managed security program, but the core purpose is the protection of assets and operations, primarily through risk reduction.

Concept tested: Information security program objectives

Topics

#Information Security Program#Program Goals#Risk Reduction#Objectives

Community Discussion

No community discussion yet for this question.

Full CISM Practice