CISM Strategic plan key components Practice Question
Which of the following are key components of an information security program's strategic plan? (Select two.)
⚠ Common exam trap
ISACA often tests the distinction between strategic (vision, roadmap) and operational/tactical (budget, procedures) components, leading candidates to mistakenly select annual budget allocation as a strategic element because it is a common management activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security program vision and objectives
The strategic plan for an information security program defines the long-term direction and governance framework. The security program vision and objectives (B) establish the overarching goals and alignment with business strategy, while the roadmap for security initiatives (D) provides the phased implementation plan to achieve those objectives. These are foundational components of strategic planning, not operational or tactical elements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annual budget allocation
Why it's wrong here
Annual budget allocation is a financial planning artefact supporting the strategy, not a component of the strategic plan itself, which defines direction, objectives, governance and risk alignment. It is tempting because funding enables any programme, but budgets follow strategy rather than forming part of it.
- ✓
Security program vision and objectives
Why this is correct
The strategic plan needs a stated direction, so the security programme vision and objectives define the desired end state and measurable outcomes. They satisfy the requirement for a key component by aligning security effort with business goals before initiatives are sequenced.
- ✗
Incident response procedures
Why it's wrong here
Incident response procedures are tactical operational documentation, not a strategic plan component; strategy covers direction, governance, risk appetite and roadmaps. It is tempting because incident response is essential to security programmes, but it belongs in operational runbooks supporting the strategy rather than constituting the strategy itself.
- ✓
Roadmap for security initiatives
Why this is correct
A strategic plan must translate intent into sequenced action, so a roadmap of security initiatives sets priorities, dependencies, timelines and resourcing. It satisfies the requirement for a key component by directing how the vision and objectives are delivered over the planning horizon.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Security program vision and objectivesCorrect answer▾
Why this is correct
The strategic plan needs a stated direction, so the security programme vision and objectives define the desired end state and measurable outcomes. They satisfy the requirement for a key component by aligning security effort with business goals before initiatives are sequenced.
✗Annual budget allocationWrong answer — click to see why▾
Why this is wrong here
Budgeting is operational, not strategic.
✗Incident response proceduresWrong answer — click to see why▾
Why this is wrong here
Procedures are operational.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.