Courseiva

CISM Information Security Governance Practice Question

A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?

⚠ Common exam trap

The trap is selecting a technically sound activity like assessing maturity or benchmarking, which are important but not the most critical for alignment with business strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Understanding the organization's strategic business objectives and risk appetite

The roadmap must directly support the organization's strategic goals and risk appetite to ensure security initiatives enable rather than hinder business objectives. Without this alignment, security investments may be misdirected or fail to gain executive support.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Benchmarking against industry peers

    Why it's wrong here

    Peer benchmarking compares performance against external organisations, but industry averages do not reflect this company's own strategic priorities. It would be the answer if the question asked how to justify budget by showing competitive positioning.

  • ✗

    Assessing current security maturity level

    Why it's wrong here

    Maturity assessment establishes the current baseline and gap, yet it does not by itself connect security investment to business objectives. It would be correct if the question asked how to determine which capabilities need development first.

  • ✗

    Reviewing recent security incidents and lessons learned

    Why it's wrong here

    Incident lessons inform control improvements, but they are retrospective and tactical, not the driver of strategic alignment. This would be the answer if the question asked how to refine detection or response capabilities after a breach.

  • ✓

    Understanding the organization's strategic business objectives and risk appetite

    Why this is correct

    Mapping initiatives to strategic objectives and risk appetite ensures every roadmap phase supports business goals rather than technology for its own sake. This satisfies the stem's alignment requirement because risk appetite defines how much exposure leadership will tolerate, letting the CISO sequence investments that match the organisation's stated direction.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.