Primary objective of a security culture

Information Security Program Management
Answer Correct answer: B — Reduce risk to acceptable levels.

Which of the following should be the PRIMARY objective for creating a culture of security within an organization?

  1. To obtain resources for information security initiatives
  2. To reduce risk to acceptable levels Correct Answer
  3. To prioritize security within the organization
  4. To demonstrate control effectiveness to senior management

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the alignment of security culture with business goals, where the trap is confusing the means of prioritizing security with the end goal of risk reduction.

The primary objective of establishing a security culture is to reduce risk to acceptable levels, ensuring security behaviors align with business goals. Community consensus confirms risk reduction as the ultimate goal over prioritization or resource allocation.

Choosing 'To prioritize security within the organization' (C) is a common mistake because while it describes the culture's function, it is not the ultimate business objective of risk management.

Community Discussion (3 comments)

sausageman 👍 5 Selected: B
B. To reduce risk to acceptable levels
Div26101994 👍 1 Selected: B
If Question was security aware culture then ans C, but as its only talks on culture its B
Saisharan 👍 1
Option C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In the ISACA CISM framework, the primary goal of the entire information security program is to support business objectives by managing risk. A culture of security ensures that every employee understands their role in protecting assets, thereby systematically reducing risk to a level acceptable to senior management.

Why the Other Options Are Wrong

Option A (obtain resources) is a potential outcome of a strong culture, not its purpose. Option C (prioritize security) is a mechanism used to achieve the goal, but risk reduction is the fundamental business driver. Option D (demonstrate control effectiveness) relates to audit and reporting rather than the cultural objective itself.

Community Comment Notes

Commenters emphasized that while a 'security aware culture' might imply prioritization (Option C), a 'culture of security' is fundamentally about operational risk mitigation. The consensus highlights that in CISM exams, 'risk reduction' is almost always the correct answer when identifying the primary objective of any security initiative.

Official Reference

Exam Strategy

For CISM questions regarding objectives, always select the option that ties security activities back to business risk management. 'Risk reduction' is the standard answer for the primary goal of any security function.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide