hardMultiple ChoiceObjective-mapped
CISM Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. ``` Audit Finding Report: Audit ID: A-2025-003 Date: 2025-03-15 Scope: Information Security Governance Finding: The organization's information security strategy does not include measurable objectives aligned with business goals. The strategy document states: 'To protect information assets from threats.' There are no defined key performance indicators (KPIs) or targets. Recommendation: Develop a security strategy with specific, measurable objectives linked to business outcomes. ```
Refer to the exhibit. The audit finding reveals a deficiency in which critical aspect of information security governance?
⚠ Common exam trap
Candidates often confuse a lack of board approval (Option B) with strategic alignment, but the finding explicitly describes a missing connection between security and business goals, not a missing approval signature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Strategic alignment between security objectives and business goals is missing.
The audit finding highlights that security initiatives are not aligned with business objectives, which is a core deficiency in strategic alignment—a critical aspect of information security governance. Without this alignment, security investments may fail to support organizational goals, leading to wasted resources and increased risk exposure. The finding directly indicates a gap between the security strategy and the business strategy, not a lack of board approval, resource allocation methodology, or risk integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Strategic alignment between security objectives and business goals is missing.
Why this is correct
Measurable objectives aligned with business goals are essential for strategic alignment.
- ✗
The board has not approved the security strategy.
Why it's wrong here
The finding does not mention lack of approval; it focuses on content.
- ✗
Resource allocation for security initiatives is not based on business impact.
Why it's wrong here
Resource allocation is not directly addressed in the finding.
- ✗
Risk management processes are not integrated with business planning.
Why it's wrong here
The finding is about strategy objectives, not risk integration.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.