CISM - Information Security Governance (17% of the exam) - Section 1.6

Conduct strategic planning including budget development, resource allocation and business case preparation for security investments.

Prepare a business case for security investments that quantifies value through ROI on security and links budget planning and resource management decisions to risk reduction outcomes. Weigh competing priorities to allocate resources to controls that deliver the greatest reduction in residual risk.

Business caseBudget planningResource managementROI on security

Practice question for this objective

Free sampleInformation Security Governancehard

An information security manager has a fixed annual budget that cannot fund every proposed initiative. Five projects compete for the money, each with a different cost and a different estimated reduction in annual loss expectancy. The board wants the budget to deliver the greatest reduction in information risk for the funds available. Which basis should most strongly drive how the manager allocates the budget across the competing projects?

  • AFund the projects in the order requested until the budget is exhausted, so each sponsoring business unit is treated even-handedly and no one is seen to be favoured over another.
  • BFund whichever projects carry the highest absolute cost first, on the basis that the most expensive initiatives address the organisation's most serious and most pressing security exposures.
  • CDistribute the budget evenly across all five projects so that every proposed initiative receives partial funding and is able to make some measurable progress this year.
  • DRank the projects by the risk reduction each delivers per unit of cost and fund them in that order, so the constrained budget removes the most risk per pound spent. Correct
Allocate a constrained security budget by ranking initiatives on risk reduction per unit of cost to maximise risk removed for the funds available. A fixed budget is a constrained-optimisation problem: ranking initiatives by risk reduction relative to their cost concentrates spend where each pound removes the most risk, which yields the greatest aggregate reduction the budget can buy.

Why A is wrong: Tempting because fairness to sponsors feels politically safe, but first-come ordering ignores cost-effectiveness and will leave the largest risk reductions unfunded if they were requested late.

Why B is wrong: Tempting because cost can feel like a proxy for seriousness, but a high price tag does not guarantee high risk reduction and can exhaust the budget on poor-value work.

Why C is wrong: Tempting because spreading funds avoids hard choices, but partial funding can leave several projects unable to deliver any usable risk reduction, wasting the budget.

Why D is correct: Correct because allocating a fixed budget by risk reduction per unit of cost maximises the total risk removed for the funds available, which is the board's stated objective.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Add a detailed technical appendix describing the tool's underlying architecture and detection algorithms, so the committee can appreciate the engineering depth that justifies the contract's substantial cost.

    Why it is wrong: Tempting because more technical depth feels rigorous, but the committee judges enterprise value, so architectural detail does not address why the spend matters to the business.

  • Add detailed technical specifications of the threat-intelligence feeds and the integrations the service supports.

    Why it is wrong: Tempting because technical depth signals rigour, but a committee evaluates value and risk, not feed formats, so more specifications address a question the committee did not ask and do not justify the spend.

  • Defer the regulatory project to the next budget cycle and formally document the resulting compliance exposure as an accepted risk.

    Why it is wrong: Tempting because it respects the funding freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship and the manager rarely has authority to accept that level of risk alone.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.