Which Approach Best Communicates Security to Senior Management?
Which of the following approaches to communication with senior management BEST enables an information security manager to maximize the effectiveness of the information security program?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests strategic alignment and risk communication; candidates frequently mistake routine meetings for impactful executive reporting.
Effective CISM communication requires translating security risks into business impact rather than focusing on tactical updates. Community consensus confirms that reporting threats aligned with business objectives yields the strongest executive engagement.
Option B is frequently selected because scheduled meetings appear proactive, yet they fail to provide the concrete business-risk context needed to justify security investments and drive organizational priorities.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Senior management prioritizes business continuity and strategic objectives over technical security metrics. Reporting on industry threats explicitly mapped to business impact demonstrates how security initiatives protect revenue, reputation, and compliance goals. This direct correlation secures executive buy-in, ensuring adequate funding and organizational support for the security program.Why the Other Options Are Wrong
Option B relies on meeting frequency rather than substantive content, making it less effective for driving strategic decisions. Option C focuses on daily operational dependencies, which falls outside the strategic purview of senior leadership. Option D merely tracks policy administrative changes without connecting them to risk reduction or business value, failing to influence executive decision-making.Community Comment Notes
Multiple users highlighted that CISM fundamentally rewards business-risk translation over administrative routines. Commenters noted that while one-on-one meetings build relationships, they do not automatically align security with enterprise goals. Consensus emphasizes that threat reporting tied to business objectives consistently outperforms operational updates in executive communications.Official Reference
Exam Strategy
Always filter security information through the lens of business impact before presenting it to executives. If an option discusses metrics, policies, or daily operations without linking to revenue, risk, or strategic goals, eliminate it immediately.
Frequently Asked Questions
Why isn't conducting regular meetings the best approach?
Meetings are a delivery channel, not a strategic communication method. Without explicit business-risk mapping, they fail to influence executive resource allocation.
How does CISM prioritize security communication levels?
CISM mandates tailoring messages to audience needs: executives require business-impact and risk data, while managers need operational metrics and policy updates.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →