CISM Information Security Program Practice Question
A financial services firm has a mature information security program. The Chief Information Security Officer (CISO) is asked by the board to demonstrate that the program is aligned with the organization's strategic objectives. Which of the following is the MOST effective way for the CISO to provide this assurance?
⚠ Common exam trap
The trap here is assuming that compliance with a standard or reporting technical metrics automatically demonstrates strategic alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map security program objectives and metrics to specific business goals and report on their contribution.
The board wants assurance that security is not a siloed function but is integrated with business strategy. Mapping security objectives and metrics to business goals provides that assurance by showing how security enables business outcomes. Other options focus on compliance, technical posture, or incident history, which do not directly address strategic alignment. The CISO should use business language and measurable contributions to demonstrate value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Present the results of the latest penetration test and vulnerability remediation statistics.
Why it's wrong here
Penetration test results and remediation statistics are tactical metrics that show technical security posture, not strategic alignment. They do not explain how the security program supports business objectives. While valuable for operational oversight, these details can overwhelm the board and fail to answer the question about alignment with strategic goals. They are better suited for security steering committee discussions.
- ✓
Map security program objectives and metrics to specific business goals and report on their contribution.
Why this is correct
Mapping security objectives and metrics to specific business goals directly demonstrates how the security program enables and supports the organization's strategy. This approach provides the board with clear line-of-sight from security activities to business outcomes, such as protecting revenue streams or enabling safe digital transformation. It is the most effective way to show strategic alignment because it uses business language and measurable contributions.
- ✗
Conduct a gap analysis against ISO/IEC 27001:2022 and present the results to the board.
Why it's wrong here
A gap analysis against ISO/IEC 27001:2022 identifies missing controls relative to a standard, but it does not directly show how security activities support business goals. The board asked for strategic alignment, not compliance status. While useful for program improvement, this approach fails to connect security outcomes to business objectives such as market expansion, customer trust, or regulatory positioning.
- ✗
Provide a summary of security incidents and the associated financial losses over the past year.
Why it's wrong here
Incident summaries and financial losses illustrate risk exposure and the cost of security failures, but they do not demonstrate alignment with strategic objectives. This information is reactive and focuses on past events rather than showing how the security program proactively supports business goals. The board may appreciate the risk context, but it does not fulfill the request for assurance of strategic alignment.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.