Courseiva

CISM Information Security Governance Practice Question

A financial services firm with a federated governance model is revising its information security strategy. The board has mandated that security investments must demonstrably support business objectives. The CISO is asked to define the MOST effective way to align security governance with business strategy. Which of the following should the CISO do FIRST?

⚠ Common exam trap

The trap here is assuming that adopting a standard framework or conducting technical assessments automatically aligns security with business strategy, when alignment first requires explicit mapping to business goals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Map information security objectives to the organization's strategic business goals and key performance indicators.

The board's mandate requires demonstrating that security investments support business objectives. Mapping security objectives to strategic business goals and KPIs creates a clear line of sight from security activities to business value, enabling prioritization and justification. This alignment step is foundational; technical assessments, awareness programs, and framework adoption are effective only after strategic alignment is established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a comprehensive vulnerability assessment across all business units to identify technical gaps.

    Why it's wrong here

    A vulnerability assessment identifies technical weaknesses but does not establish alignment with business strategy. While useful for tactical planning, it fails to address the board's mandate to demonstrate how security supports business objectives. This activity is typically performed after strategic alignment is defined and priorities are set.

  • ✗

    Implement a security awareness program tailored to each business unit's specific risks.

    Why it's wrong here

    A tailored awareness program addresses human risk but does not directly align security governance with business strategy. It is an operational control that should follow strategic alignment. Without first mapping security objectives to business goals, awareness efforts may not target the areas of greatest business impact or satisfy the board's requirement.

  • ✗

    Adopt a recognized security framework such as ISO/IEC 27001 to standardize controls across the organization.

    Why it's wrong here

    Adopting a framework provides a structured control baseline but does not by itself align security with business strategy. Frameworks are valuable for governance consistency, yet they must be tailored to business objectives. This action is premature without first understanding how security supports the organization's strategic goals, especially in a federated model.

  • ✓

    Map information security objectives to the organization's strategic business goals and key performance indicators.

    Why this is correct

    Mapping security objectives to business goals and KPIs directly aligns security governance with business strategy, ensuring investments support mandated outcomes. This first step establishes traceability and allows the CISO to prioritize initiatives based on business value, which is essential for board-level justification in a federated model where accountability is shared.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.