What Best Facilitates Developing Information Security Procedures?
Which of the following BEST facilitates the development of information security procedures that effectively support the information security policy?
Community Votes
54% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of the policy-to-procedure hierarchy, where candidates often mistakenly prioritize generic industry standards over foundational asset classification.
This CISM question tests whether asset classification or external benchmarks better drive procedure development. While debated by candidates, ISACA guidelines confirm that classifying information assets provides the necessary context to design targeted, policy-aligned security procedures.
Option A (Aligning procedures with industry best practices) is frequently chosen because benchmarks seem practical, but they lack the organization-specific context needed to tailor procedures to actual classified assets.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Asset classification establishes the value and sensitivity of data, which directly dictates the rigor and scope of required security procedures. ISACA’s governance framework emphasizes that procedures must be proportionate to asset criticality to effectively operationalize high-level policies. Without classification, controls become either misaligned or inefficiently resource-heavy.Why the Other Options Are Wrong
Industry best practices (A) and external benchmarking (D) provide useful references but cannot replace organization-specific risk context. Considering systemic risk events (C) addresses enterprise-wide threats rather than guiding granular procedure drafting. These options support strategy but do not directly facilitate procedure development like asset classification does.Community Comment Notes
Candidates are split between A and B, reflecting real-world confusion between standardized frameworks and internal governance. Commenters supporting A highlight the appeal of proven external standards, while those backing B correctly note that classification drives tailored implementation. This mirrors typical exam traps where practical-sounding answers override ISACA’s policy-first methodology.Official Reference
Exam Strategy
Always trace back to ISACA’s governance hierarchy: policies set direction, asset classification defines requirements, and procedures execute them. When choosing between external benchmarks and internal context, prioritize the option that enables organization-specific control design.
Frequently Asked Questions
Why isn't aligning with industry best practices better here?
Best practices offer general guidance but lack the organization-specific context needed to tailor procedures to your actual classified assets and business risks.
Does asset classification come before or after risk assessment?
Classification precedes formal risk assessment. You must know what you are protecting and its value before you can accurately evaluate threats and vulnerabilities.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →