Courseiva

CISM Information Security Governance Practice Question

An organization's information security strategy is being developed. The CISO wants to ensure that the strategy supports business objectives while managing risk. Which of the following should be the PRIMARY input to the strategy development process?

⚠ Common exam trap

The trap here is selecting a technical or compliance input, such as vulnerability reports or frameworks, as the primary driver, when the business strategy should always come first to ensure alignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The organization's business strategy and objectives.

The primary input to security strategy development must be the organization's business strategy and objectives. This ensures that security efforts are directly tied to what the business is trying to achieve, enabling risk management that supports rather than hinders business goals. Other inputs, such as frameworks or technical reports, are secondary and should be used to inform implementation once the business direction is clear.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Industry best practice frameworks such as ISO/IEC 27001.

    Why it's wrong here

    Frameworks like ISO/IEC 27001 provide valuable guidance and structure, but they are not the primary input. They help implement the strategy once business objectives are understood. Starting with a framework can lead to a checkbox approach that does not address the organization's specific business context, risk appetite, or strategic goals, resulting in a generic and potentially misaligned security program.

  • ✗

    The IT department's technology roadmap.

    Why it's wrong here

    The IT technology roadmap is important for understanding planned technology changes, but it is subordinate to the business strategy. Security strategy should influence and align with IT plans, not be driven by them. If the IT roadmap is the primary input, security may become a technical exercise rather than a business-aligned function, potentially missing broader business risks and opportunities.

  • ✗

    The latest vulnerability scan reports.

    Why it's wrong here

    Vulnerability scan reports are tactical outputs that inform specific remediation efforts but do not provide the strategic direction needed for developing an overall security strategy. They address existing weaknesses rather than future business goals. Using them as the primary input would result in a reactive strategy focused on fixing current issues rather than proactively supporting business objectives.

  • ✓

    The organization's business strategy and objectives.

    Why this is correct

    The business strategy and objectives are the primary input because they define what the organization aims to achieve, and security must enable those goals. By starting with business strategy, the CISO ensures that security initiatives are relevant, prioritized, and funded appropriately. Without this input, the security strategy risks being disconnected from business needs and perceived as a cost center rather than an enabler.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.