Certified Information Security Manager (CISM)Information Security Risk ManagementEasy
An organization is developing its information security program. The information security manager is tasked with ensuring that the program aligns with business objectives. Which of the following actions is MOST crucial to achieve this alignment?
- AEngage with business unit leaders to understand their objectives and risk tolerance.
- BImplement a robust security awareness training program for all employees.
- CConduct a comprehensive technical vulnerability assessment of all systems.
- DBenchmark the program against industry best practices and standards.
Show answer & explanationAnswer & explanation
Correct answer: A. Engage with business unit leaders to understand their objectives and risk tolerance.
Aligning the information security program with business objectives requires understanding what those objectives are and the associated business risks. Engaging directly with business unit leaders provides this crucial insight, ensuring security efforts support, rather than hinder, business goals and are tailored to the organization's specific risk tolerance.
Why the other options are wrong
- B. Security awareness is an important component of a security program but does not, by itself, ensure overall program alignment with business objectives.
- C. Technical assessments identify vulnerabilities but don't directly inform how security should support business goals.
- D. Benchmarking is useful for identifying gaps but doesn't inherently align security with specific business objectives.
Business-Security Alignment
The process of ensuring that information security strategies, controls, and investments support and enable an organization's overall business objectives.
- Requires communication between security and business leaders.
- Involves understanding business risk appetite.
- Ensures security is a business enabler, not just a cost center.
Memory trick: Align security: talk to business, know their goals.