CISM Information Security Governance Practice Question
A CISO is updating the enterprise information security strategy. The organization's business strategy now emphasizes rapid expansion into cloud-based services and third-party partnerships. Which of the following should be the CISO's FIRST action to ensure the security strategy remains aligned with the business strategy?
⚠ Common exam trap
The trap here is assuming that immediately updating policies or conducting technical tests demonstrates alignment, when in fact strategic alignment begins with understanding the relationship between business drivers and security objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map the current security program objectives to the new business drivers and identify gaps.
The correct answer is to map current security program objectives to the new business drivers and identify gaps. This step ensures the security strategy is directly aligned with the organization's cloud expansion and partnership goals. It provides a factual basis for adjusting policies, budgets, and controls, and it demonstrates to stakeholders that security is a business enabler. Without this mapping, subsequent actions risk being disconnected from strategic intent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately update the security policy to include cloud and third-party requirements.
Why it's wrong here
Updating policy before understanding the alignment gaps is premature. Policies should reflect the strategic direction, but without first assessing how current objectives map to new business drivers, the policy changes may be misdirected or incomplete. This approach risks addressing symptoms rather than the root alignment issue.
- ✓
Map the current security program objectives to the new business drivers and identify gaps.
Why this is correct
Mapping current security objectives to new business drivers directly ensures strategic alignment by revealing where security may not support cloud expansion and partnerships. This gap analysis is foundational before making changes, as it provides the context needed to prioritize investments and adjust the security strategy to enable the business rather than hinder it.
- ✗
Present the current security budget to the board for approval.
Why it's wrong here
Presenting the budget before aligning the strategy may result in funding requests that do not reflect the new business priorities. The board expects security investments to enable business goals. Without first mapping objectives to business drivers, the budget presentation lacks the strategic justification needed and may be rejected or misaligned with expansion plans.
- ✗
Conduct a penetration test of the existing cloud environments.
Why it's wrong here
A penetration test is a tactical control validation activity, not a strategic alignment step. While useful for identifying vulnerabilities, it does not help the CISO understand whether the security strategy supports the business strategy. Performing it first would skip the necessary strategic analysis and could waste resources on areas not critical to the new business direction.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.