CISM - Information Security Governance (17% of the exam) - Section 1.4

Develop and maintain an information security strategy that is aligned with organisational goals and objectives.

Develop an information security strategy that is explicitly tied to business objectives and expressed in a security roadmap and mission statement. Recognise that strategic alignment requires continuous review to ensure security investments remain relevant as organisational priorities evolve.

Strategic alignmentBusiness objectivesSecurity roadmapMission statement

Practice question for this objective

Free sampleInformation Security Governancehard

An organisation with an approved, well-aligned security strategy completes a major acquisition that adds a regulated line of business and shifts the corporate strategy towards a new market. The information security manager wants the security strategy to remain aligned as these changes take effect. Which practice best maintains strategic alignment over time?

  • AFreeze the approved strategy for its full multi-year term to preserve stability and avoid disrupting committed initiatives
  • BReview the strategy against the revised corporate objectives whenever the business direction changes materially, and realign initiatives accordingly Correct
  • CDefer any change until the next scheduled three-year strategy refresh, then incorporate all accumulated business changes at once
  • DDelegate alignment to each business unit so the units adapt the strategy locally to fit their own changing circumstances
Maintaining strategic alignment means reviewing and realigning the security strategy whenever corporate objectives change materially, not only at scheduled intervals. Alignment is not a one-off act performed at approval; a material change such as an acquisition into a regulated market alters the objectives the strategy serves, so the strategy must be reviewed and its initiatives realigned in response to keep security supporting where the business is now heading.

Why A is wrong: Tempting because stability protects in-flight delivery, but freezing the strategy lets it drift from a changed business and defeats the purpose of keeping it aligned.

Why B is correct: Correct because maintaining alignment requires revisiting the strategy against business objectives when they change materially, so the security strategy tracks the organisation rather than lagging it.

Why C is wrong: Tempting because a single periodic refresh is efficient, yet waiting years to absorb a market shift leaves the strategy misaligned through the very period the change matters most.

Why D is wrong: Tempting because local adaptation seems responsive, but devolving alignment fragments the enterprise strategy and removes the manager's accountability for coherent governance.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • It records the sequenced initiatives and dependencies the function will deliver over the coming planning period

    Why it is wrong: Tempting because a mission feels like a plan, but sequenced initiatives and dependencies are the roadmap's job, so this describes a different document rather than the mission's value.

  • It records the maturity score the function has achieved against an external framework so progress can be reported to regulators.

    Why it is wrong: Tempting because maturity reporting supports governance, but a maturity score is a measurement output, not a mission statement, which expresses enduring purpose rather than a point-in-time rating.

  • A prioritised list of the technical controls that address the most severe vulnerabilities identified in the latest penetration test.

    Why it is wrong: Tempting because severe vulnerabilities feel urgent and concrete, but a control list driven by a single test is tactical output that does not show alignment with enterprise priorities, so the board is unlikely to see strategic value.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.