CISM Primary driver for business alignment Practice Question
An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?
⚠ Common exam trap
The trap here is that candidates often mistake compliance (A) as the primary driver because it is a visible and mandatory requirement, but CISM stresses that compliance is a subset of governance, not the overarching goal of program alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Achieving the organization's strategic goals
The primary driver for aligning the security program with business objectives is to ensure that security initiatives directly support and enable the organization's strategic goals. Without this alignment, security becomes a cost center rather than a business enabler, and resources may be misallocated to activities that do not advance the enterprise's mission. CISM emphasizes that security governance must be integrated with business strategy to justify investment and demonstrate value to stakeholders.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance with industry regulations
Why it's wrong here
Regulatory compliance sets a minimum baseline and varies by jurisdiction; it does not by itself align security with business objectives across a multinational. Compliance is tempting because it is measurable and mandatory, and it would be the correct driver where the organisation's sole obligation is satisfying a specific regulatory framework.
- ✗
Reducing information security costs
Why it's wrong here
Cost reduction is an outcome of alignment, not its driver; the primary driver is enabling business strategy and objectives through risk-informed security. Reducing spend is tempting because budgets are constrained, and cost optimisation would be the correct focus when the mandate is explicitly to cut security expenditure without changing business goals.
- ✓
Achieving the organization's strategic goals
Why this is correct
Aligning security with business objectives ensures controls enable rather than obstruct the organisation's strategic goals, satisfying the stem's requirement for a primary driver. Security exists to support mission delivery, so strategic alignment directs investment and risk decisions toward outcomes the business actually needs.
- ✗
Implementing the latest security technologies
Why it's wrong here
Technology adoption is a tactical response, not a driver; alignment starts from business objectives and derives controls, rather than selecting tools first. Deploying the latest security technologies is tempting because vendors and trends promote it, and it would be correct when a validated capability gap requires a specific new control.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Achieving the organization's strategic goalsCorrect answer▾
Why this is correct
Aligning security with business objectives ensures controls enable rather than obstruct the organisation's strategic goals, satisfying the stem's requirement for a primary driver. Security exists to support mission delivery, so strategic alignment directs investment and risk decisions toward outcomes the business actually needs.
✗Compliance with industry regulationsWrong answer — click to see why▾
Why this is wrong here
Compliance is a requirement but not the primary driver; the program must support business goals to be effective.
✗Reducing information security costsWrong answer — click to see why▾
Why this is wrong here
Cost reduction is a possible outcome but not the primary driver for alignment.
✗Implementing the latest security technologiesWrong answer — click to see why▾
Why this is wrong here
Adopting new technologies is a tactic, not the primary driver.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.