How to Determine Security Program Alignment with Business Strategy?
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
Community Votes
60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your ability to distinguish between defining alignment with stakeholders versus actively measuring it through established business-linked metrics like KPIs.
Aligning an information security program with business strategy requires measurable metrics, with experts and candidates agreeing that reviewing Key Performance Indicators (KPIs) is the most effective validation method.
Option D (Engage business process owners) is frequently chosen because stakeholder input seems intuitive for strategy, but it defines goals rather than objectively measuring ongoing program alignment.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Key performance indicators (KPIs) serve as the primary mechanism for translating abstract business strategies into measurable security outcomes. By reviewing established KPIs, a security manager can objectively verify whether controls and initiatives are delivering the expected business value. This metric-driven approach aligns directly with ISACA’s emphasis on continuous monitoring and evidence-based governance. As noted by top-voted comments, KPIs provide the quickest and most reliable snapshot of strategic alignment.Why the Other Options Are Wrong
Evaluating business continuity testing results only validates recovery capabilities, not broader strategic alignment. Assessing incident business impacts highlights past failures or vulnerabilities but does not proactively measure ongoing program alignment with corporate goals. While engaging business process owners is crucial for goal-setting, it yields qualitative insights rather than the objective, trackable data required to confirm actual alignment.Community Comment Notes
Candidates frequently debate between reviewing KPIs and consulting process owners, reflecting a common exam dilemma. Commenters who selected D correctly recognized that stakeholder input defines strategy, but missed that the question specifically asks how to determine alignment, which requires measurement. Users supporting C emphasized that KPIs bridge the gap between security operations and executive expectations. This mirrors real-world governance where metrics, not meetings, prove alignment.Official Reference
Exam Strategy
When a CISM question asks how to measure or determine alignment, always look for quantitative or standardized metrics first. Reserve stakeholder engagement for questions asking how to define, design, or gain buy-in for security objectives.
Frequently Asked Questions
Why isn't engaging business process owners the best way?
Stakeholder engagement defines strategic goals, but KPIs provide the objective, ongoing measurements needed to verify actual program alignment.
Do KPIs need to be set by security teams?
No. Effective security KPIs must be co-developed with business leaders to ensure they directly reflect corporate priorities and risk appetite.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →