A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?
Anchoring each security initiative to a named strategic business objective makes the roadmap traceable to business intent, satisfying the alignment requirement. Security priorities then shift as business strategy shifts, rather than being driven by technology or compliance alone, which is what the CISO's multi-year horizon demands.
Why this answer
A multi-year security roadmap must be driven by the organization's strategic business objectives to ensure security investments enable rather than obstruct business goals. Aligning initiatives with business strategy ensures the roadmap is prioritized by business value, secures executive sponsorship, and remains relevant as the business evolves. This is the foundational principle of business-aligned security governance.
Exam trap
CISM often tests whether candidates default to compliance or threat-driven roadmaps, but the exam consistently rewards business-strategy alignment as the primary driver — candidates who pick 'compliance requirements only' or 'latest threat intelligence' fall for the reactive/technical trap.
How to eliminate wrong answers
Option A is wrong because prioritizing by security team capacity is an internal resource constraint, not a strategic alignment driver — it can lead to under-investing in high-business-value initiatives. Option C is wrong because basing the roadmap solely on the latest threat intelligence is reactive and may not reflect the organization's specific risk profile or business priorities. Option D is wrong because compliance-only roadmaps are minimum-bar and do not address business strategy, competitive advantage, or risk appetite.