Courseiva

CISM Information Security Programme Practice Question

During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?

⚠ Common exam trap

The trap here is substituting an operational metric such as scan results or budget variance for the business strategy when judging strategic alignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The organization's current business strategy and objectives

Strategic alignment means the security programme's priorities, investments, and risk decisions support the organization's business strategy. The business strategy is therefore the authoritative input against which the plan is validated. Technical scan data, procurement records, and budget variance are useful programme inputs, but each measures execution or exposure rather than whether security is pointed in the same direction as the business.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The latest vulnerability scan results from the production environment

    Why it's wrong here

    Scan results show technical exposure at a point in time and inform tactical remediation, but they say nothing about whether the programme supports business direction. A clean scan in a business unit being divested is wasted effort, while an aligned programme may tolerate known vulnerabilities on a system being decommissioned. Scan data answers a different question than strategic alignment.

  • ✓

    The organization's current business strategy and objectives

    Why this is correct

    Security strategy exists to protect the business as it pursues its goals, so the business strategy is the reference point for alignment. Changes in markets, products, acquisitions, or digital initiatives alter the risk profile and required controls. Reviewing the security plan against anything else cannot demonstrate that security investments support what the organization is actually trying to achieve.

  • ✗

    The vendor list from the most recent procurement cycle

    Why it's wrong here

    Procurement activity reflects purchasing decisions already made and provides useful third-party risk input, but it does not define the organization's direction. Using it as the alignment reference would let security follow spending rather than strategy, potentially over-investing in legacy areas while new business initiatives proceed without proportionate protection.

  • ✗

    The previous year's security budget versus actual expenditure

    Why it's wrong here

    Budget variance shows financial discipline within the security function, not whether the programme matches business goals. A perfectly executed budget can still fund the wrong priorities if the business has pivoted. This metric belongs in programme performance reporting, but it cannot validate strategic alignment, which requires comparison against business objectives.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.