Certified Information Security Manager (CISM)Information Security GovernanceMedium
A CISO is developing a new information security strategy. To ensure the strategy effectively supports the organization's overall mission and objectives, which of the following is the MOST important initial step?
- AUnderstand the organization's strategic business plan and risk appetite.
- BBenchmark the organization's security posture against industry best practices.
- CIdentify and prioritize the latest cyber threats and attack vectors.
- DConduct a comprehensive technical vulnerability assessment of existing systems.
Show answer & explanationAnswer & explanation
Correct answer: A. Understand the organization's strategic business plan and risk appetite.
An information security strategy must be aligned with the organization's overarching business objectives and risk appetite. Understanding these foundational elements is the most important initial step to ensure the security strategy is relevant, impactful, and supported.
Why the other options are wrong
- B. Benchmarking is useful for comparison, but it doesn't define what is *right* for the specific organization without understanding its unique business goals and risk tolerance.
- C. Identifying threats is crucial, but without understanding the business context, it's difficult to prioritize which threats matter most to the organization's specific mission and assets.
- D. While important for tactical security, a technical assessment doesn't provide the strategic business context needed to *develop* the overall security strategy.
Strategic Alignment (InfoSec)
The principle of ensuring that information security strategies, investments, and activities are directly linked to and support the organization's overall business objectives, mission, and strategic plan.
- Essential for gaining executive support and resource allocation.
- Ensures security efforts deliver business value.
- Involves understanding business goals, risk appetite, and regulatory landscape.
Memory trick: Before you build security, know the business's heart and its risk start.