First Step in Aligning InfoSec Strategy with Business Goals?
Which of the following should be done FIRST when developing an information security strategy that is aligned with organizational goals?
Community Votes
55% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Assesses the correct sequence in strategic planning, where candidates often mistakenly jump to risk assessment instead of establishing business alignment first.
Building an effective information security strategy requires prioritizing business context before technical controls. Candidates consistently confirm that evaluating security’s impact on organizational objectives is the mandatory initial phase.
Option C is frequently selected because risk evaluation appears actionable, yet it bypasses the foundational requirement of understanding how security supports core business priorities.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Selecting option B establishes the necessary business context before any technical initiatives are planned. ISACA explicitly mandates that strategy formulation begins by mapping security capabilities to enterprise objectives, ensuring resources target high-priority areas. Without this alignment, subsequent risk assessments or project selections lack strategic relevance and fail to deliver measurable business value.Why the Other Options Are Wrong
Option A introduces KRIs prematurely, as metrics cannot be meaningfully defined without first understanding business priorities. Option C attempts risk assessment too early, ignoring that risk identification depends entirely on the established organizational context. Option D proposes project selection before validation, which leads to misaligned investments and wasted budget on irrelevant security initiatives.Community Comment Notes
Multiple users highlight that understanding business impact directly informs all downstream activities. Comment [2] correctly notes that risk assessment builds upon the context provided by organizational goals, making it a secondary step. Comment [6] reinforces that grasping the business context is foundational, preventing disconnected security roadmaps.Exam Strategy
Always prioritize business alignment over technical execution in CISM scenarios. Ask yourself whether the action defines the problem space or merely jumps to solutions, as strategic roles require contextual understanding first.
Frequently Asked Questions
Why isn't risk assessment the first step?
Risk assessment requires defined business context and priority levels to evaluate threats effectively. Without knowing organizational goals, risk scoring lacks strategic relevance.
When should KRIs be established?
Key risk indicators must be derived after security initiatives are mapped to business objectives. Defining them earlier results in arbitrary metrics that fail to track actual enterprise value.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →