How to Determine Security Program Alignment with Business Strategy?

Information Security Governance
Answer Correct answer: C — Review key performance indicators (KPIs) to quantitatively validate whether the information security program consistently supports overarching business strategy.

Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?

  1. Evaluate the results of business continuity testing.
  2. Evaluate the business impact of incidents.
  3. Review key performance indicators (KPIs). Correct Answer
  4. Engage business process owners.

Community Votes

C
60%
D
40%

60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to distinguish between defining alignment with stakeholders versus actively measuring it through established business-linked metrics like KPIs.

Aligning an information security program with business strategy requires measurable metrics, with experts and candidates agreeing that reviewing Key Performance Indicators (KPIs) is the most effective validation method.

Option D (Engage business process owners) is frequently chosen because stakeholder input seems intuitive for strategy, but it defines goals rather than objectively measuring ongoing program alignment.

Community Discussion (4 comments)

SHERLOCKAWS 👍 1 Selected: D
Answer is D. Engage business process owners. Because alignment means that the security program supports and enables the business, rather than being a separate or disconnected function. To truly understand if your security objectives align with business goals, you need input from the process owners. KPIs measure performance, but not necessarily strategic alignment, unless those KPIs are built around business value which again is provided by the process owner.
Josef4CISM 👍 2 Selected: C
The question asks about the most EFFECTIVE way. KPI's are aligned with the business objectives and by reviewing them, the security manager can quickly assess the business alignment.
mdmdmd 👍 1 Selected: D
the keyword here should be stakeholder since they understand the goal and processes, and can tell or provide insight on the alignment ...
ServerBrain 👍 1 Selected: C
C. Review key performance indicators (KPIs).

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Key performance indicators (KPIs) serve as the primary mechanism for translating abstract business strategies into measurable security outcomes. By reviewing established KPIs, a security manager can objectively verify whether controls and initiatives are delivering the expected business value. This metric-driven approach aligns directly with ISACA’s emphasis on continuous monitoring and evidence-based governance. As noted by top-voted comments, KPIs provide the quickest and most reliable snapshot of strategic alignment.

Why the Other Options Are Wrong

Evaluating business continuity testing results only validates recovery capabilities, not broader strategic alignment. Assessing incident business impacts highlights past failures or vulnerabilities but does not proactively measure ongoing program alignment with corporate goals. While engaging business process owners is crucial for goal-setting, it yields qualitative insights rather than the objective, trackable data required to confirm actual alignment.

Community Comment Notes

Candidates frequently debate between reviewing KPIs and consulting process owners, reflecting a common exam dilemma. Commenters who selected D correctly recognized that stakeholder input defines strategy, but missed that the question specifically asks how to determine alignment, which requires measurement. Users supporting C emphasized that KPIs bridge the gap between security operations and executive expectations. This mirrors real-world governance where metrics, not meetings, prove alignment.

Official Reference

Exam Strategy

When a CISM question asks how to measure or determine alignment, always look for quantitative or standardized metrics first. Reserve stakeholder engagement for questions asking how to define, design, or gain buy-in for security objectives.

Frequently Asked Questions

Why isn't engaging business process owners the best way?

Stakeholder engagement defines strategic goals, but KPIs provide the objective, ongoing measurements needed to verify actual program alignment.

Do KPIs need to be set by security teams?

No. Effective security KPIs must be co-developed with business leaders to ensure they directly reflect corporate priorities and risk appetite.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide