What Does an Information Security Strategy Primarily Input To?
An organization's information security strategy should be the PRIMARY input to which of the following?
Community Votes
71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of the governance hierarchy, where test-takers often mistakenly reverse the flow by assuming the strategy dictates organizational risk appetite instead of structuring the governance framework.
In CISM governance hierarchies, the information security strategy serves as the foundational driver for designing the security governance framework. Exam candidates overwhelmingly agree that option A correctly reflects this top-down alignment.
Option D is frequently chosen because candidates confuse strategic direction with executive risk tolerance; however, risk appetite is established by senior leadership first, while the security strategy adapts to it and subsequently shapes the governance framework.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The information security strategy outlines how security will support business objectives and must directly feed into the design of the security governance framework. This framework operationalizes the strategy by defining roles, responsibilities, policies, and control structures. ISACA’s governance model explicitly positions the strategy as the primary input for structuring governance mechanisms.Why the Other Options Are Wrong
Enterprise risk scenario development relies on asset valuation and threat modeling rather than the security strategy itself. Security program metrics are derived from the governance framework and control objectives to measure effectiveness, not from the high-level strategy. Organizational risk appetite is determined by the board and executive management based on overall business goals, meaning the security strategy aligns to it rather than driving it.Community Comment Notes
Multiple high-voted comments confirm that the security governance framework is the direct downstream output of the security strategy. Candidates who selected D noted confusion between strategic planning and executive risk tolerance, but official guidance clarifies that governance design is the immediate next step after strategy formulation. Consensus strongly supports A as the authoritative answer [Comment 1][Comment 2].Official Reference
Exam Strategy
Always map CISM questions to the top-down governance hierarchy: Business Objectives → Risk Appetite → Information Security Strategy → Governance Framework → Policies & Controls. When stuck, ask whether the option represents a strategic directive or an operational implementation mechanism.
Frequently Asked Questions
Why isn't organizational risk appetite the primary input?
Risk appetite is defined by the board and senior management based on overall business objectives, not by the information security strategy. The strategy must align to this pre-established appetite before shaping the governance framework.
How does security strategy relate to program metrics?
Metrics are derived from the governance framework and control objectives to measure operational effectiveness. They are a downstream output, not a direct input from the high-level strategy.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →