Which Approach Best Communicates Security to Senior Management?

CISM Governance & Business Alignment
Answer Correct answer: A — Reporting industry threats with potential impact to business objectives secures executive alignment and justifies security investments.

Which of the following approaches to communication with senior management BEST enables an information security manager to maximize the effectiveness of the information security program?

  1. Reporting on industry security threats with potential impact to business objectives Correct Answer
  2. Conducting periodic one-on-one meetings to align security with business objectives
  3. Participating in operational review meetings to discuss daily operations and dependencies
  4. Providing regular status of updates to security policies and standards

Community Votes

B
50%
A
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests strategic alignment and risk communication; candidates frequently mistake routine meetings for impactful executive reporting.

Effective CISM communication requires translating security risks into business impact rather than focusing on tactical updates. Community consensus confirms that reporting threats aligned with business objectives yields the strongest executive engagement.

Option B is frequently selected because scheduled meetings appear proactive, yet they fail to provide the concrete business-risk context needed to justify security investments and drive organizational priorities.

Community Discussion (4 comments)

SHERLOCKAWS 👍 1 Selected: A
Correct answer is A: Reporting on industry security threats with potential impact to business objectives. Because it connects security to business risk, which is exactly what CISM teaches is most effective for engaging leadership. About B. Conducting periodic one-on-one meetings to align security with business objectives. This sounds great in theory, but it’s not as scalable or impactful plus that one-on-ones may not reach the full senior management team.
bronay 👍 1 Selected: A
A. Reporting threat
Jay2021aws 👍 1
A. Reporting on industry security threats with potential impact to business objectives. This approach keeps senior management informed about relevant external threats that could affect the organization's business objectives, allowing them to make informed decisions about resource allocation and risk mitigation strategies. It demonstrates the proactive stance of the information security manager in addressing potential risks to the organization's operations and aligns the information security program with the broader business goals and priorities. Therefore, choice A is the most effective approach in this context.
jcisco123 👍 2 Selected: B
B. Conducting periodic one-on-one meetings to align security with business objectives

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Senior management prioritizes business continuity and strategic objectives over technical security metrics. Reporting on industry threats explicitly mapped to business impact demonstrates how security initiatives protect revenue, reputation, and compliance goals. This direct correlation secures executive buy-in, ensuring adequate funding and organizational support for the security program.

Why the Other Options Are Wrong

Option B relies on meeting frequency rather than substantive content, making it less effective for driving strategic decisions. Option C focuses on daily operational dependencies, which falls outside the strategic purview of senior leadership. Option D merely tracks policy administrative changes without connecting them to risk reduction or business value, failing to influence executive decision-making.

Community Comment Notes

Multiple users highlighted that CISM fundamentally rewards business-risk translation over administrative routines. Commenters noted that while one-on-one meetings build relationships, they do not automatically align security with enterprise goals. Consensus emphasizes that threat reporting tied to business objectives consistently outperforms operational updates in executive communications.

Official Reference

Exam Strategy

Always filter security information through the lens of business impact before presenting it to executives. If an option discusses metrics, policies, or daily operations without linking to revenue, risk, or strategic goals, eliminate it immediately.

Frequently Asked Questions

Why isn't conducting regular meetings the best approach?

Meetings are a delivery channel, not a strategic communication method. Without explicit business-risk mapping, they fail to influence executive resource allocation.

How does CISM prioritize security communication levels?

CISM mandates tailoring messages to audience needs: executives require business-impact and risk data, while managers need operational metrics and policy updates.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide