exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 65 discussion

Actual exam question from Isaca's CISM
Question #: 65
Topic #: 1
[All CISM Questions]

An information security manager MUST have an understanding of the organization's business goals to:

  • A. relate information security to change management.
  • B. develop an information security strategy.
  • C. develop operational procedures
  • D. define key performance indicators (KPIs).
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 12 months ago
Selected Answer: B
B. develop an information security strategy. An information security manager MUST have an understanding of the organization's business goals to develop an information security strategy. The security strategy should align with the overall business objectives and support the organization's mission and goals. Without understanding the business goals, it would be difficult for the information security manager to determine the appropriate level of security and prioritize the allocation of resources to protect the organization's most critical assets and data. An understanding of the business goals can also help in relating information security to change management, developing operational procedures and defining key performance indicators (KPIs) but it's crucial for developing an information security strategy.
upvoted 9 times
...
kong230790
Most Recent 1 month, 1 week ago
Selected Answer: B
Role of the Information Security Manager: An ISM is responsible for implementing and managing the information security program, which must align with the organization's goals and priorities. Developing or updating a strategy is part of this responsibility, as the ISM ensures that tactical and operational activities serve the broader business needs.
upvoted 1 times
...
simon205
8 months, 3 weeks ago
Selected Answer: D
B . Information security strategy should be defined by CISO , not IS manager . Manager should be more operation .
upvoted 2 times
...
Viperhunter
1 year, 1 month ago
Selected Answer: B
An understanding of the organization's business goals is crucial for an information security manager to develop an effective information security strategy. The strategy should align with and support the overall business objectives and priorities of the organization.
upvoted 1 times
...
Cyberbug2021
1 year, 1 month ago
Selected Answer: B
obviously
upvoted 2 times
...
Viperhunter
1 year, 1 month ago
Selected Answer: B
Understanding the organization's business goals is crucial for developing an information security strategy that aligns with and supports those goals. A well-crafted information security strategy should be closely tied to the overall business objectives and priorities of the organization. This ensures that security measures are not only effective in protecting assets but also contribute to the achievement of broader business goals. While relating information security to change management (option A), developing operational procedures (option C), and defining key performance indicators (KPIs) (option D) are important aspects of information security management, they are all influenced and guided by the overarching context of the organization's business goals.
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
B. develop an information security strategy. Understanding the organization's business goals is essential for developing an effective information security strategy. Information security should align with and support the broader business objectives and mission. Without a clear understanding of the organization's goals and priorities, it becomes challenging to develop a security strategy that addresses the specific risks and requirements of the business. While understanding business goals is crucial for developing an information security strategy, it also plays a role in other areas like relating information security to change management (A), developing operational procedures (C), and defining key performance indicators (KPIs) (D). However, developing a security strategy is often the primary area where this understanding is foundational.
upvoted 1 times
...
Agamennore
1 year, 4 months ago
Selected Answer: B
Absolutely B
upvoted 1 times
...
Nillanash
1 year, 5 months ago
D. define key performance indicators (KPIs) s correct. This is the correct answer because the information security officer does not develop information security strategy. The Strategy is developed by senior leaders and managers—such as the CEO, executive team, and board of directors.
upvoted 2 times
...
rugerfan17
1 year, 7 months ago
Selected Answer: B
Develop the strategy according to business goals. Once you have the strategy, you define KPI's to measure success.
upvoted 1 times
...
richck102
1 year, 7 months ago
B. develop an information security strategy.
upvoted 2 times
...
STUDYER2
1 year, 11 months ago
Selected Answer: B
STRATEGY ALWAYS LINK TO BUSINESS GOAL
upvoted 4 times
cidigi
10 months ago
Is not asking that... This is irrelevant here. Is the IS Manager responsible for the Strategy? No he is not
upvoted 1 times
...
...
Antonivs
1 year, 11 months ago
Selected Answer: B
B, for sure
upvoted 2 times
...
Prospect57
1 year, 12 months ago
Selected Answer: B
B should be the correct answer.
upvoted 4 times
...
aokisan
2 years ago
Selected Answer: D
understanding goal unites with KPI.
upvoted 2 times
...
Ziggybooboo
2 years, 1 month ago
Agreed
upvoted 1 times
...
skhalid
2 years, 1 month ago
yes the correct answer is B
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago