Courseiva

CISM Information Security Governance Practice Question

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

⚠ Common exam trap

CISM often tests whether candidates default to compliance or threat-driven roadmaps, but the exam consistently rewards business-strategy alignment as the primary driver — candidates who pick 'compliance requirements only' or 'latest threat intelligence' fall for the reactive/technical trap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Align security initiatives with the organization's strategic business objectives

A multi-year security roadmap must be driven by the organization's strategic business objectives to ensure security investments enable rather than obstruct business goals. Aligning initiatives with business strategy ensures the roadmap is prioritized by business value, secures executive sponsorship, and remains relevant as the business evolves. This is the foundational principle of business-aligned security governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Prioritize initiatives based on security team capacity

    Why it's wrong here

    Team capacity is an internal resourcing constraint, not a statement of business direction, so prioritising by it aligns the roadmap with the security team rather than the business. It is tempting because capacity planning keeps delivery realistic, and it is the right lens when scheduling feasible work within a fixed headcount.

  • ✓

    Align security initiatives with the organization's strategic business objectives

    Why this is correct

    Anchoring each security initiative to a named strategic business objective makes the roadmap traceable to business intent, satisfying the alignment requirement. Security priorities then shift as business strategy shifts, rather than being driven by technology or compliance alone, which is what the CISO's multi-year horizon demands.

  • ✗

    Base the roadmap on the latest industry threat intelligence

    Why it's wrong here

    Threat intelligence describes the external adversary landscape, not the organisation's business goals, so it cannot by itself align the roadmap with strategy. It is tempting because intelligence is timely and actionable, and it is the correct primary input when the objective is tactical detection and response improvement rather than multi-year strategic alignment.

  • ✗

    Create the roadmap based on compliance requirements only

    Why it's wrong here

    Compliance requirements capture regulatory minimums, not the organisation's strategic objectives, so a roadmap built solely on them cannot align with business strategy. It is tempting because compliance mandates are concrete, auditable and defensible, making them the right driver when the goal is certification or regulatory remediation rather than strategic alignment.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.