CISM - Information Security Governance - Section 1.6

Conduct strategic planning including budget development, resource allocation and business case preparation for security investments.

Prepare a business case for security investments that quantifies value through ROI on security and links budget planning and resource management decisions to risk reduction outcomes. Weigh competing priorities to allocate resources to controls that deliver the greatest reduction in residual risk.

Business caseBudget planningResource managementROI on security

Practice question for this objective

Free sampleInformation Security Governancehard

An information security manager has a fixed annual budget that cannot fund every proposed initiative. Five projects compete for the money, each with a different cost and a different estimated reduction in annual loss expectancy. The board wants the budget to deliver the greatest reduction in information risk for the funds available. Which basis should most strongly drive how the manager allocates the budget across the competing projects?

  • AFund the projects in the order requested until the budget is exhausted, so each sponsoring business unit is treated even-handedly and no one is seen to be favoured over another.
  • BFund whichever projects carry the highest absolute cost first, on the basis that the most expensive initiatives address the organisation's most serious and most pressing security exposures.
  • CDistribute the budget evenly across all five projects so that every proposed initiative receives partial funding and is able to make some measurable progress this year.
  • DRank the projects by the risk reduction each delivers per unit of cost and fund them in that order, so the constrained budget removes the most risk per pound spent. Correct
Allocate a constrained security budget by ranking initiatives on risk reduction per unit of cost to maximise risk removed for the funds available. A fixed budget is a constrained-optimisation problem: ranking initiatives by risk reduction relative to their cost concentrates spend where each pound removes the most risk, which yields the greatest aggregate reduction the budget can buy.

Why A is wrong: Tempting because fairness to sponsors feels politically safe, but first-come ordering ignores cost-effectiveness and will leave the largest risk reductions unfunded if they were requested late.

Why B is wrong: Tempting because cost can feel like a proxy for seriousness, but a high price tag does not guarantee high risk reduction and can exhaust the budget on poor-value work.

Why C is wrong: Tempting because spreading funds avoids hard choices, but partial funding can leave several projects unable to deliver any usable risk reduction, wasting the budget.

Why D is correct: Correct because allocating a fixed budget by risk reduction per unit of cost maximises the total risk removed for the funds available, which is the board's stated objective.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.