How to Encourage Business Units to Adopt Security Roles?
Which of the following is the BEST approach for encouraging business units to assume their roles and responsibilities in an information security program?
Community Votes
73% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question evaluates your ability to prioritize cultural change over procedural steps, with the common trap being the selection of risk assessments or audits as primary drivers of behavioral adoption.
This CISM question tests how to drive organizational security ownership through leadership engagement rather than technical controls or audits. The community consensus confirms that targeted awareness for senior management is the most effective catalyst for business unit compliance.
Candidates frequently choose risk assessment because it is a foundational governance activity, but it identifies threats rather than actively motivating departments to own security tasks.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Senior management sets the tone at the top, making their buy-in essential for cascading security expectations down to operational teams. Conducting an awareness program specifically for executives ensures they understand their fiduciary and oversight duties, which directly translates into resource allocation and policy enforcement for business units.Why the Other Options Are Wrong
Independent audits and risk assessments are diagnostic tools that measure existing gaps rather than motivate ongoing participation. Developing controls focuses on technical implementation instead of addressing the human and cultural factors required for sustained accountability across departments.Community Comment Notes
Multiple users highlighted the keyword "encourage," noting that awareness initiatives directly influence behavior and cultural adoption. Commenters emphasized that executive sponsorship creates a ripple effect, where business units naturally align with security goals when leadership prioritizes them.Official Reference https://www.isaca.org/resources/cism-review-manual
Exam Strategy
When questions emphasize motivation, culture, or adoption, prioritize people-centric interventions like training and executive advocacy over technical or compliance activities. Always map the desired outcome to the lever that directly influences human behavior first.
Frequently Asked Questions
Why isn't a risk assessment better for driving security ownership?
Risk assessments identify vulnerabilities and quantify exposure but do not inherently motivate staff to change behaviors or take ownership of security tasks.
How does executive awareness translate to business unit compliance?
When leaders receive targeted training, they champion security policies internally, allocate necessary resources, and hold their teams accountable for meeting security objectives.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →