Primary objective of a security culture
Which of the following should be the PRIMARY objective for creating a culture of security within an organization?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the alignment of security culture with business goals, where the trap is confusing the means of prioritizing security with the end goal of risk reduction.
The primary objective of establishing a security culture is to reduce risk to acceptable levels, ensuring security behaviors align with business goals. Community consensus confirms risk reduction as the ultimate goal over prioritization or resource allocation.
Choosing 'To prioritize security within the organization' (C) is a common mistake because while it describes the culture's function, it is not the ultimate business objective of risk management.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In the ISACA CISM framework, the primary goal of the entire information security program is to support business objectives by managing risk. A culture of security ensures that every employee understands their role in protecting assets, thereby systematically reducing risk to a level acceptable to senior management.Why the Other Options Are Wrong
Option A (obtain resources) is a potential outcome of a strong culture, not its purpose. Option C (prioritize security) is a mechanism used to achieve the goal, but risk reduction is the fundamental business driver. Option D (demonstrate control effectiveness) relates to audit and reporting rather than the cultural objective itself.Community Comment Notes
Commenters emphasized that while a 'security aware culture' might imply prioritization (Option C), a 'culture of security' is fundamentally about operational risk mitigation. The consensus highlights that in CISM exams, 'risk reduction' is almost always the correct answer when identifying the primary objective of any security initiative.Official Reference
Exam Strategy
For CISM questions regarding objectives, always select the option that ties security activities back to business risk management. 'Risk reduction' is the standard answer for the primary goal of any security function.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →