CISSP - Security and Risk Management - Section 1.3

Evaluate and apply security governance principles aligned with organisational goals, mission, and strategy.

Describe how governance frameworks align security strategy with organisational mission, goals, and due diligence obligations. Choose the appropriate security control framework for a given organisational context and explain how governance structures assign accountability.

governance frameworksorganisational alignmentdue diligencesecurity control frameworks

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A newly appointed CISO at a mid-sized manufacturing firm finds that the information security programme has historically been driven entirely by the IT department, with controls selected by engineers based on technical merit. The board has asked the CISO to demonstrate that security investment is aligned with the business. Which action should the CISO take FIRST to establish governance alignment?

  • AEngage with executive leadership to identify business objectives, risk appetite, and critical assets before defining a security strategy. Correct
  • BAdopt the NIST Cybersecurity Framework and map all existing technical controls to its categories to show coverage.
  • CCommission an external penetration test to baseline the current technical posture and report findings to the board.
  • DRestructure the security team to report directly to the CEO and publish an updated information security policy.
Security governance alignment starts with understanding business mission, objectives, and risk appetite before selecting frameworks or controls. CISSP treats security governance as the translation of organisational goals into a security strategy. Without first eliciting mission, objectives, and risk appetite from senior leadership, any framework adoption or control selection risks defending the wrong things or constraining the business. The strategy is the artefact that ties leadership intent to subsequent control selection.

Why A is correct: Governance alignment begins by understanding mission, objectives, and risk appetite from senior leadership; only then can the security strategy be shaped to support, rather than constrain, the business.

Why B is wrong: Mapping controls to a framework is useful but it documents what already exists rather than confirming the programme supports the business mission, so it answers the wrong question first.

Why C is wrong: A penetration test produces a technical snapshot but does not address the governance gap the board raised; tactical findings without strategic context perpetuate the IT-led problem.

Why D is wrong: Reporting line changes and a fresh policy are reasonable later actions, but they will lack credibility until the CISO can show the strategy reflects what leadership actually values.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.