Courseiva

CISM Information Security Program Practice Question

A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?

⚠ Common exam trap

The trap here is focusing on technical controls or compliance instead of framing the business case in terms of financial risk and business enablement, which resonates with executives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An analysis of the potential financial impact of security incidents and how the program will mitigate those risks to protect revenue and reputation.

An analysis of potential financial impact and risk mitigation directly aligns the security program with business objectives by showing how it protects revenue and reputation. Executives are more likely to fund initiatives that clearly address business risk and demonstrate a return on investment. This approach makes the business case compelling and strategic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A detailed list of all security controls that will be implemented and their associated costs.

    Why it's wrong here

    A list of controls and costs is tactical and does not effectively communicate how the security program supports business objectives. Executives are more interested in risk reduction and business enablement than in technical controls. While costs are important, they should be presented in the context of risk mitigation and business value. This option fails to make the strategic connection that the CISO needs to secure funding.

  • ✗

    A comparison of the company's security posture to industry benchmarks and competitor practices.

    Why it's wrong here

    Benchmarking can provide context, but it does not directly show how the security program supports the company's specific business objectives. Executives may find it interesting, but it lacks the financial and risk-based justification that drives funding decisions. Without a clear link to the company's own risk exposure and business goals, this option is less persuasive than a tailored financial impact analysis.

  • ✓

    An analysis of the potential financial impact of security incidents and how the program will mitigate those risks to protect revenue and reputation.

    Why this is correct

    Executives prioritize risk and financial impact. By quantifying potential losses from incidents and showing how the security program reduces those risks, the CISO directly ties security to business objectives like revenue protection and reputation management. This approach speaks the language of the business and makes a compelling case for investment. It demonstrates that security is not just a cost center but a business enabler.

  • ✗

    A timeline for achieving compliance with relevant regulations such as GDPR or HIPAA.

    Why it's wrong here

    Compliance is a requirement, but it is not the same as managing risk to support business objectives. While compliance can be a driver, executives are more concerned with protecting the business from financial and reputational harm. A compliance timeline alone does not demonstrate how the program will enable business growth or reduce risk beyond regulatory minimums. It is a narrow view that may not secure adequate funding.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.