CISM Information Security Governance Practice Question
A CISO is developing a set of information security policies for a healthcare organization. The organization must comply with HIPAA and internal privacy requirements. Which of the following should be the PRIMARY consideration when drafting the security policy framework?
⚠ Common exam trap
The trap here is prioritizing practical constraints like cost or technical feasibility over strategic and regulatory alignment when drafting policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alignment with the organization's mission, goals, and regulatory obligations.
Security policies must first align with the organization's mission, goals, and regulatory obligations to ensure they support business objectives and comply with laws like HIPAA. Cost, technical feasibility, and IT preferences are secondary considerations that influence implementation but should not dictate policy content. This alignment ensures policies are relevant, enforceable, and legally sound.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The preferences of the IT department regarding policy structure and wording.
Why it's wrong here
IT preferences are not a primary driver for policy content. Policies are governance instruments that should reflect organizational requirements and risk appetite, not departmental convenience. Involving IT is useful for implementation, but policy drafting must prioritize legal, regulatory, and business alignment.
- ✓
Alignment with the organization's mission, goals, and regulatory obligations.
Why this is correct
Alignment with mission, goals, and regulatory obligations is the primary consideration because policies must support business objectives and ensure compliance. In healthcare, HIPAA and privacy requirements are mandatory, so policies must directly address them while enabling the organization's mission. This alignment ensures relevance, buy-in, and legal defensibility.
- ✗
The technical feasibility of enforcing each policy with existing tools.
Why it's wrong here
Technical feasibility is a practical concern, but it is secondary to aligning policies with business and regulatory needs. Policies should drive technology choices, not be constrained by current tools. If a policy is required for compliance, the organization must acquire or develop the necessary capabilities.
- ✗
The cost of implementing each policy control across the organization.
Why it's wrong here
Cost is an important factor in implementation, but it should not be the primary consideration when drafting policies. Policies must first reflect legal, regulatory, and business requirements. Focusing on cost could lead to inadequate controls and compliance failures, especially in a healthcare context where patient data protection is critical.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.