First Step in Aligning InfoSec Strategy with Business Goals?

Answer Correct answer: B — Determine information security's impact on the achievement of organizational goals.

Which of the following should be done FIRST when developing an information security strategy that is aligned with organizational goals?

  1. Establish a security risk framework with key risk indicators (KRIs).
  2. Determine information security's impact on the achievement of organizational goals. Correct Answer
  3. Assess information security risk associated with the organizational goals
  4. Select information security projects related to the organizational goals.

Community Votes

C
55%
B
45%

55% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Assesses the correct sequence in strategic planning, where candidates often mistakenly jump to risk assessment instead of establishing business alignment first.

Building an effective information security strategy requires prioritizing business context before technical controls. Candidates consistently confirm that evaluating security’s impact on organizational objectives is the mandatory initial phase.

Option C is frequently selected because risk evaluation appears actionable, yet it bypasses the foundational requirement of understanding how security supports core business priorities.

Community Discussion (6 comments)

SHERLOCKAWS 👍 1 Selected: B
Answer is B: Determine information security's impact on the achievement of organizational goals. Because understanding the business context is the first step to building a strategy that truly aligns. C. Assess information security risk associated with the organizational goals, is also critical, but only after you know how security relates to those goals.
Booict 👍 2
B - Understanding how information security supports or affects organizational goals is essential. It ensures that security initiatives align with business objectives and priorities. Whereas C is - it comes after understanding the impact. Risk assessment builds upon the context provided by organizational goals
Marcelus1714 👍 2 Selected: C
Going with C. The B says "impact on the achievement of organizational goals.". On the "achievement of organizational goals"? does not make sense. C seems more good, it talks about "Assess"
POWNED 👍 2 Selected: C
B does not make sense, going with C.
FantasyDream 👍 4 Selected: B
B. Determine information security's impact on the achievement of organizational goals.
PeteyPete 👍 2 Selected: C
C. Assess information security risk associated with the organizational goals

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Selecting option B establishes the necessary business context before any technical initiatives are planned. ISACA explicitly mandates that strategy formulation begins by mapping security capabilities to enterprise objectives, ensuring resources target high-priority areas. Without this alignment, subsequent risk assessments or project selections lack strategic relevance and fail to deliver measurable business value.

Why the Other Options Are Wrong

Option A introduces KRIs prematurely, as metrics cannot be meaningfully defined without first understanding business priorities. Option C attempts risk assessment too early, ignoring that risk identification depends entirely on the established organizational context. Option D proposes project selection before validation, which leads to misaligned investments and wasted budget on irrelevant security initiatives.

Community Comment Notes

Multiple users highlight that understanding business impact directly informs all downstream activities. Comment [2] correctly notes that risk assessment builds upon the context provided by organizational goals, making it a secondary step. Comment [6] reinforces that grasping the business context is foundational, preventing disconnected security roadmaps.

Exam Strategy

Always prioritize business alignment over technical execution in CISM scenarios. Ask yourself whether the action defines the problem space or merely jumps to solutions, as strategic roles require contextual understanding first.

Frequently Asked Questions

Why isn't risk assessment the first step?

Risk assessment requires defined business context and priority levels to evaluate threats effectively. Without knowing organizational goals, risk scoring lacks strategic relevance.

When should KRIs be established?

Key risk indicators must be derived after security initiatives are mapped to business objectives. Defining them earlier results in arbitrary metrics that fail to track actual enterprise value.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide