ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is reviewing an organization's information security strategy. The organization has recently acquired several smaller companies, each with its own established security practices. Which of the following is the MOST critical first step for the CISA to evaluate regarding the overall strategy's effectiveness?

  1. AEvaluate the training programs for employees on security awareness and incident reporting.
  2. BReview the alignment of the security strategy with the organization's business objectives and risk appetite.
  3. CExamine the technical controls implemented for data loss prevention and intrusion detection.
  4. DAssess the budget allocation for security tools and personnel across all acquired entities.
Show answer & explanation

Correct answer: B. Review the alignment of the security strategy with the organization's business objectives and risk appetite.

The most critical first step for a CISA when reviewing an information security strategy, especially after acquisitions, is to ensure its alignment with the organization's overarching business objectives and risk appetite. Without this foundational alignment, even well-implemented controls may not effectively support the business or manage the right risks.

Why the other options are wrong

  • A. Employee training is an operational aspect of security, following strategic definition.
  • C. Technical controls are part of strategy implementation, not the initial evaluation of the strategy itself.
  • D. Budget allocation is important but comes after strategic alignment has been established.

Security Strategy Alignment

The process of ensuring an organization's information security strategy directly supports its business objectives and operates within its defined risk appetite.

  • Foundation for effective security.
  • Guides resource allocation and control selection.
  • Must adapt to organizational changes like acquisitions.

Memory trick: Align the strategy to the business, like a compass to true north.

More Domain 5: Protection of Information Assets questions