How to Encourage Business Units to Adopt Security Roles?

Information Security Governance
Answer Correct answer: C — Conduct an awareness program for senior management to drive organizational security ownership and ensure business units adopt their assigned responsibilities.

Which of the following is the BEST approach for encouraging business units to assume their roles and responsibilities in an information security program?

  1. Engage an independent security audit.
  2. Perform a risk assessment.
  3. Conduct an awareness program for senior management. Correct Answer
  4. Develop controls and countermeasures.

Community Votes

C
73%
B
27%

73% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question evaluates your ability to prioritize cultural change over procedural steps, with the common trap being the selection of risk assessments or audits as primary drivers of behavioral adoption.

This CISM question tests how to drive organizational security ownership through leadership engagement rather than technical controls or audits. The community consensus confirms that targeted awareness for senior management is the most effective catalyst for business unit compliance.

Candidates frequently choose risk assessment because it is a foundational governance activity, but it identifies threats rather than actively motivating departments to own security tasks.

Community Discussion (6 comments)

Josef4CISM 👍 2 Selected: C
Weird wording - but I guess the question asks about how to create awareness for information security. You can do so by creating awareness starting from the senior management and continue to lower organizational levels.
Booict 👍 2 Selected: C
When senior management is aware and supportive, they can effectively communicate the importance of information security to their respective business units, fostering a culture of security throughout the organization
ServerBrain 👍 1 Selected: C
C. Conduct an awareness program for senior management.
MMK777 👍 3 Selected: C
I belevie its C
pgonza 👍 3 Selected: B
I think B (Perform a risk assessment) is correct. Any ideas?
Evedzy 👍 4
isn't key word is encourage? C is the answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Senior management sets the tone at the top, making their buy-in essential for cascading security expectations down to operational teams. Conducting an awareness program specifically for executives ensures they understand their fiduciary and oversight duties, which directly translates into resource allocation and policy enforcement for business units.

Why the Other Options Are Wrong

Independent audits and risk assessments are diagnostic tools that measure existing gaps rather than motivate ongoing participation. Developing controls focuses on technical implementation instead of addressing the human and cultural factors required for sustained accountability across departments.

Community Comment Notes

Multiple users highlighted the keyword "encourage," noting that awareness initiatives directly influence behavior and cultural adoption. Commenters emphasized that executive sponsorship creates a ripple effect, where business units naturally align with security goals when leadership prioritizes them.

Official Reference https://www.isaca.org/resources/cism-review-manual

Exam Strategy

When questions emphasize motivation, culture, or adoption, prioritize people-centric interventions like training and executive advocacy over technical or compliance activities. Always map the desired outcome to the lever that directly influences human behavior first.

Frequently Asked Questions

Why isn't a risk assessment better for driving security ownership?

Risk assessments identify vulnerabilities and quantify exposure but do not inherently motivate staff to change behaviors or take ownership of security tasks.

How does executive awareness translate to business unit compliance?

When leaders receive targeted training, they champion security policies internally, allocate necessary resources, and hold their teams accountable for meeting security objectives.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide