Courseiva

CISM Information Security Program Practice Question

A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?

⚠ Common exam trap

The trap here is focusing on technical or fear-based arguments instead of linking security to the business outcomes executives care about.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Demonstrate how security enables the achievement of business objectives and protects revenue streams

The most effective approach is to demonstrate how security enables business objectives and protects revenue streams. This aligns security with the executives' strategic priorities, positioning it as a value driver rather than a cost. By showing that security supports growth, innovation, and customer trust, the CISO can build a compelling business case that resonates with executive leadership and secures necessary funding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Highlight the technical sophistication of the proposed security controls

    Why it's wrong here

    Executives are generally not interested in technical details; they care about business outcomes. Focusing on technical sophistication may confuse or alienate them, and it does not address their concerns about revenue growth and market expansion. The business case should speak the language of the business, emphasizing risk reduction in terms of business impact and enablement, not technical features. Technical details can be discussed later with technical stakeholders.

  • ✗

    Emphasize the potential cost savings from preventing security incidents

    Why it's wrong here

    Cost savings are important, but executives focused on revenue growth may not be motivated primarily by cost avoidance. This approach frames security as a defensive measure rather than an enabler of business objectives. While cost savings can be part of the value proposition, leading with them may fail to resonate with executives who prioritize growth and market opportunities. The business case should instead highlight how security supports and enables revenue-generating activities.

  • ✗

    Present industry benchmarks showing the average cost of a data breach

    Why it's wrong here

    Industry benchmarks can create urgency, but they are generic and may not directly relate to the organization's specific business context. Executives focused on growth might view this as fear-based selling rather than a strategic investment. The business case should connect security to the organization's own objectives, such as protecting new revenue streams or enabling safe expansion into new markets. Benchmarks alone do not demonstrate how security will help achieve those goals.

  • ✓

    Demonstrate how security enables the achievement of business objectives and protects revenue streams

    Why this is correct

    This approach aligns security with the executives' priorities by showing that security is not just a cost center but a business enabler. It highlights how security measures can protect revenue, facilitate market expansion, and build customer trust. By directly linking security to business objectives, the CISO can secure executive support and funding more effectively. This strategic alignment is a core principle of a mature information security program and is essential for gaining buy-in from business leaders.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.