What Does an Information Security Strategy Primarily Input To?

Information Security Governance
Answer Correct answer: A — Design the security governance framework to translate the information security strategy into structured policies, roles, and control implementations.

An organization's information security strategy should be the PRIMARY input to which of the following?

  1. Security governance framework design Correct Answer
  2. Enterprise risk scenario development
  3. Security program metrics
  4. Organizational risk appetite

Community Votes

A
71%
D
29%

71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of the governance hierarchy, where test-takers often mistakenly reverse the flow by assuming the strategy dictates organizational risk appetite instead of structuring the governance framework.

In CISM governance hierarchies, the information security strategy serves as the foundational driver for designing the security governance framework. Exam candidates overwhelmingly agree that option A correctly reflects this top-down alignment.

Option D is frequently chosen because candidates confuse strategic direction with executive risk tolerance; however, risk appetite is established by senior leadership first, while the security strategy adapts to it and subsequently shapes the governance framework.

Community Discussion (3 comments)

Yahealborini 👍 3 Selected: A
A. Security governance framework design
bronay 👍 2 Selected: D
D. Organisation risk appetite
maisarajarrah 👍 2 Selected: A
A. Security governance framework design

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The information security strategy outlines how security will support business objectives and must directly feed into the design of the security governance framework. This framework operationalizes the strategy by defining roles, responsibilities, policies, and control structures. ISACA’s governance model explicitly positions the strategy as the primary input for structuring governance mechanisms.

Why the Other Options Are Wrong

Enterprise risk scenario development relies on asset valuation and threat modeling rather than the security strategy itself. Security program metrics are derived from the governance framework and control objectives to measure effectiveness, not from the high-level strategy. Organizational risk appetite is determined by the board and executive management based on overall business goals, meaning the security strategy aligns to it rather than driving it.

Community Comment Notes

Multiple high-voted comments confirm that the security governance framework is the direct downstream output of the security strategy. Candidates who selected D noted confusion between strategic planning and executive risk tolerance, but official guidance clarifies that governance design is the immediate next step after strategy formulation. Consensus strongly supports A as the authoritative answer [Comment 1][Comment 2].

Official Reference

Exam Strategy

Always map CISM questions to the top-down governance hierarchy: Business Objectives → Risk Appetite → Information Security Strategy → Governance Framework → Policies & Controls. When stuck, ask whether the option represents a strategic directive or an operational implementation mechanism.

Frequently Asked Questions

Why isn't organizational risk appetite the primary input?

Risk appetite is defined by the board and senior management based on overall business objectives, not by the information security strategy. The strategy must align to this pre-established appetite before shaping the governance framework.

How does security strategy relate to program metrics?

Metrics are derived from the governance framework and control objectives to measure operational effectiveness. They are a downstream output, not a direct input from the high-level strategy.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide