Certified Information Security Manager (CISM)Information Security GovernanceEasy

A CISO is developing an information security strategy. To ensure the strategy effectively supports the organization's mission and objectives, it MUST be directly derived from which of the following?

  1. AThe organization's overall enterprise risk management (ERM) framework and risk appetite.
  2. BIndustry best practices and common security frameworks (e.g., NIST CSF, ISO 27001).
  3. CBenchmarking against the security postures of leading competitors in the same industry.
  4. DA comprehensive assessment of current and emerging cyber threats.
Show answer & explanation

Correct answer: A. The organization's overall enterprise risk management (ERM) framework and risk appetite.

The information security strategy MUST be directly derived from the organization's overall enterprise risk management (ERM) framework and risk appetite. This ensures that security efforts are aligned with the organization's tolerance for risk and its strategic objectives.

Why the other options are wrong

  • B. Best practices and frameworks provide guidance, but the strategy must be tailored to the organization's specific risk and business context.
  • C. Benchmarking is useful for comparison but does not dictate the organization's unique strategic security needs based on its own risk appetite.
  • D. Threat assessments inform the strategy but are not the primary driver for its overall direction and alignment with business objectives.

Strategic Security Alignment

The process of ensuring that an organization's information security strategy is fully integrated with and directly supports its overall business strategy, mission, and enterprise risk management framework.

  • Security as a business enabler, not just a technical function.
  • Must reflect organizational risk appetite.
  • Guided by ERM and business objectives.

Memory trick: The security map must start from the enterprise's risk compass.

More Information Security Governance questions