Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A CISO is presenting to the executive leadership on the organization's information security program. The executives are concerned about aligning security investments with the overall business strategy. Which of the following actions demonstrates the BEST alignment of information security with business objectives?

  1. APrioritizing security initiatives based on their impact on critical business processes and assets.
  2. BFocusing security efforts primarily on compliance with all regulatory mandates.
  3. CAchieving the highest possible security maturity level according to a recognized framework.
  4. DImplementing the latest security technologies recommended by industry analysts.
Show answer & explanation

Correct answer: A. Prioritizing security initiatives based on their impact on critical business processes and assets.

Aligning security investments with business strategy means prioritizing efforts that protect the most critical business processes and assets. This ensures that security resources are directed where they provide the most value to the business, directly supporting its objectives and risk appetite, rather than being driven by technology trends, generalized compliance, or abstract maturity levels.

Why the other options are wrong

  • B. While compliance is critical, it's a baseline, not necessarily a strategic alignment with *all* business objectives beyond regulatory adherence.
  • C. Achieving high maturity is a worthy goal but can be pursued for its own sake without direct linkage to specific business value or risk reduction for critical assets.
  • D. Implementing the 'latest' technology doesn't guarantee alignment with specific business needs or risk tolerance.

Business-Security Alignment

Business-security alignment is the process of ensuring that information security strategies, investments, and practices directly support and enable an organization's overall business objectives and risk management goals.

  • Security becomes an enabler, not just a cost center.
  • Prioritizes protection of critical business assets.
  • Involves communication and understanding between security and business leaders.

Memory trick: Security must serve the business, not just exist.

More Information Security Risk Management questions