CISM - Information Security Governance - Section 1.4

Develop and maintain an information security strategy that is aligned with organisational goals and objectives.

Develop an information security strategy that is explicitly tied to business objectives and expressed in a security roadmap and mission statement. Recognise that strategic alignment requires continuous review to ensure security investments remain relevant as organisational priorities evolve.

Strategic alignmentBusiness objectivesSecurity roadmapMission statement

Practice question for this objective

Free sampleInformation Security Governancehard

An organisation with an approved, well-aligned security strategy completes a major acquisition that adds a regulated line of business and shifts the corporate strategy towards a new market. The information security manager wants the security strategy to remain aligned as these changes take effect. Which practice best maintains strategic alignment over time?

  • AFreeze the approved strategy for its full multi-year term to preserve stability and avoid disrupting committed initiatives
  • BReview the strategy against the revised corporate objectives whenever the business direction changes materially, and realign initiatives accordingly Correct
  • CDefer any change until the next scheduled three-year strategy refresh, then incorporate all accumulated business changes at once
  • DDelegate alignment to each business unit so the units adapt the strategy locally to fit their own changing circumstances
Maintaining strategic alignment means reviewing and realigning the security strategy whenever corporate objectives change materially, not only at scheduled intervals. Alignment is not a one-off act performed at approval; a material change such as an acquisition into a regulated market alters the objectives the strategy serves, so the strategy must be reviewed and its initiatives realigned in response to keep security supporting where the business is now heading.

Why A is wrong: Tempting because stability protects in-flight delivery, but freezing the strategy lets it drift from a changed business and defeats the purpose of keeping it aligned.

Why B is correct: Correct because maintaining alignment requires revisiting the strategy against business objectives when they change materially, so the security strategy tracks the organisation rather than lagging it.

Why C is wrong: Tempting because a single periodic refresh is efficient, yet waiting years to absorb a market shift leaves the strategy misaligned through the very period the change matters most.

Why D is wrong: Tempting because local adaptation seems responsive, but devolving alignment fragments the enterprise strategy and removes the manager's accountability for coherent governance.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.