Courseiva

CISM Strategic plan key components Practice Question

Which of the following are key components of an information security program's strategic plan? (Select two.)

⚠ Common exam trap

ISACA often tests the distinction between strategic (vision, roadmap) and operational/tactical (budget, procedures) components, leading candidates to mistakenly select annual budget allocation as a strategic element because it is a common management activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security program vision and objectives

The strategic plan for an information security program defines the long-term direction and governance framework. The security program vision and objectives (B) establish the overarching goals and alignment with business strategy, while the roadmap for security initiatives (D) provides the phased implementation plan to achieve those objectives. These are foundational components of strategic planning, not operational or tactical elements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Annual budget allocation

    Why it's wrong here

    Annual budget allocation is a financial planning artefact supporting the strategy, not a component of the strategic plan itself, which defines direction, objectives, governance and risk alignment. It is tempting because funding enables any programme, but budgets follow strategy rather than forming part of it.

  • ✓

    Security program vision and objectives

    Why this is correct

    The strategic plan needs a stated direction, so the security programme vision and objectives define the desired end state and measurable outcomes. They satisfy the requirement for a key component by aligning security effort with business goals before initiatives are sequenced.

  • ✗

    Incident response procedures

    Why it's wrong here

    Incident response procedures are tactical operational documentation, not a strategic plan component; strategy covers direction, governance, risk appetite and roadmaps. It is tempting because incident response is essential to security programmes, but it belongs in operational runbooks supporting the strategy rather than constituting the strategy itself.

  • ✓

    Roadmap for security initiatives

    Why this is correct

    A strategic plan must translate intent into sequenced action, so a roadmap of security initiatives sets priorities, dependencies, timelines and resourcing. It satisfies the requirement for a key component by directing how the vision and objectives are delivered over the planning horizon.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.

✓Security program vision and objectivesCorrect answer▾

Why this is correct

The strategic plan needs a stated direction, so the security programme vision and objectives define the desired end state and measurable outcomes. They satisfy the requirement for a key component by aligning security effort with business goals before initiatives are sequenced.

✗Annual budget allocationWrong answer — click to see why▾

Why this is wrong here

Budgeting is operational, not strategic.

✗Incident response proceduresWrong answer — click to see why▾

Why this is wrong here

Procedures are operational.

Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.