Courseiva
easyMultiple Choice

CISM Practice Question: Is developing its information security strategy

An organization is developing its information security strategy. Which of the following should be the PRIMARY driver for defining security objectives?

⚠ Common exam trap

The trap here is that candidates often select 'regulatory compliance requirements' as the primary driver because they confuse legal necessity with strategic priority, but CISM emphasizes that security governance must be business-driven, not compliance-driven.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business objectives

Business objectives are the primary driver for defining security objectives because information security exists to enable the organization to achieve its mission and strategic goals. Security objectives must align with and support business objectives to ensure that resources are allocated effectively and that security controls are prioritized based on risk to the business, not just compliance or generic practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Industry best practices

    Why it's wrong here

    Industry best practices are generic and may not reflect the organisation's own risk profile or business objectives. They are tempting because peer benchmarks offer ready guidance, and would be correct when benchmarking maturity, but security objectives must be driven by the organisation's business objectives and risk appetite.

  • ✗

    Historical security incidents

    Why it's wrong here

    Historical incidents describe past events, which cannot define forward-looking objectives for a changing threat landscape. They are tempting because they evidence real gaps, and would be correct as input to a lessons-learned review or control gap analysis, but strategy objectives must derive from business objectives and risk appetite.

  • ✓

    Business objectives

    Why this is correct

    Security objectives exist to enable the organisation's mission; aligning them with business objectives ensures controls support strategic goals and risk appetite, satisfying the stem's requirement for the primary driver rather than technology or compliance alone.

  • ✗

    Regulatory compliance requirements

    Why it's wrong here

    Regulatory compliance sets a minimum baseline, not the primary driver; objectives scoped only to mandates leave risks outside scope unaddressed. It is tempting because non-compliance carries penalties, and compliance would be the correct driver for a mandated control programme, but strategy must align to business objectives and risk appetite.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.