CISM Information Security Programme Practice Question
A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?
⚠ Common exam trap
The trap here is assuming that technical or compliance benefits alone will justify security spending, but leadership typically requires financial justification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quantify the potential financial impact of security incidents and demonstrate cost avoidance.
To gain approval from cost-focused leadership, the security manager should quantify the financial impact of risks and demonstrate cost avoidance. This aligns security with business goals and provides a clear return on investment. Other approaches, while valid, may not address the primary concern of cost reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Emphasize that the initiative is required by industry best practices.
Why it's wrong here
While best practices are important, they may not resonate with leadership focused on cost reduction. Without a clear financial justification, the initiative may be seen as discretionary. Best practices alone do not demonstrate tangible return on investment or cost savings.
- ✗
Highlight that the initiative will improve the organization's security posture.
Why it's wrong here
Improving security posture is a valid goal, but it is abstract and may not appeal to a cost-focused leadership. The business case should link security improvements to financial outcomes. Without quantification, the argument may be perceived as a cost center rather than an investment.
- ✓
Quantify the potential financial impact of security incidents and demonstrate cost avoidance.
Why this is correct
Quantifying financial impact and cost avoidance speaks directly to leadership's focus on cost reduction. It translates security benefits into business terms, showing how the initiative can prevent losses. This approach aligns security with business objectives and provides a compelling rationale for investment.
- ✗
Mention that the initiative will help with compliance with regulations.
Why it's wrong here
Compliance is necessary but often viewed as a cost of doing business. Leadership focused on cost reduction may see compliance as unavoidable but not value-adding. The business case should go beyond compliance to show financial benefits such as avoiding fines or reducing insurance premiums.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.