exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 492 discussion

Actual exam question from Isaca's CISM
Question #: 492
Topic #: 1
[All CISM Questions]

Which of the following should be the PRIMARY basis for determining information security objectives?

  • A. Business strategy
  • B. Regulatory requirements
  • C. Information security strategy
  • D. Data classification
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dravidian
Highly Voted 1 year, 8 months ago
Selected Answer: C
I do believe the right answer is option C. Information security strategy is derived/based on the business strategy. Objectives are steps to fulfill a strategy so information security objectives will be primarily based on the information security strategy.
upvoted 7 times
karanvp
1 year, 6 months ago
Is strategy not a plan to achieve the objectives? Thought strategy is based on the objectives.
upvoted 3 times
...
...
shervin2s
Most Recent 10 months ago
Selected Answer: A
A. Business strategy
upvoted 1 times
...
xcjxcj
10 months, 4 weeks ago
Selected Answer: C
Below also from chatgpt, which make more sense than simply post the question Yes, that's correct. Security objectives are typically derived from the organization's information security strategy. The security strategy outlines the overall goals and direction for security within the organization, and the security objectives are specific, measurable targets that support the strategy. These objectives help ensure that security efforts are aligned with the organization's overall goals and priorities.
upvoted 1 times
xcjxcj
10 months, 4 weeks ago
My question is Security objectives are primarily based on information security strategy
upvoted 1 times
...
...
AlexJacobson
11 months, 3 weeks ago
Selected Answer: C
It's C. ChatGPT addicts in the comments can go ahead and fail the exam since they obviously don't know even the basics, let alone advanced stuff. The process goes like this: You look at the business strategy and based on that you create information security strategy. And then you define the objectives through which you realize the strategy. Then you create KGI, and so on..
upvoted 2 times
...
oluchecpoint
1 year, 4 months ago
Selected Answer: A
A. Business strategy. While regulatory requirements, information security strategy, and data classification are important considerations for information security, they should all align with and support the broader goals and objectives of the organization's business strategy. Information security should be seen as an enabler of the business strategy rather than a standalone goal. By aligning information security objectives with the business strategy, an organization can ensure that its security efforts are focused on protecting the most critical assets and achieving the overall goals of the business.
upvoted 2 times
...
Goseu
1 year, 6 months ago
Selected Answer: A
A seems correct .
upvoted 1 times
...
richck102
1 year, 6 months ago
A. Business strategy
upvoted 1 times
...
wello
1 year, 7 months ago
Selected Answer: C
C. Information security strategy
upvoted 1 times
...
CarlPTY07
1 year, 10 months ago
Selected Answer: A
ISACA : A
upvoted 3 times
...
Souvik124
1 year, 11 months ago
The PRIMARY basis for determining information security objectives should be the organization's business strategy (Option A).
upvoted 2 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: A
A. Business strategy should be the PRIMARY basis for determining information security objectives. Information security objectives should be aligned with the organization's overall business strategy and objectives in order to support the organization's mission and goals. This means that the information security program should be designed to meet the specific needs of the organization, and that it should be continuously reviewed and updated to ensure that it remains aligned with changing business needs. Determining information security objectives based on business strategy will help ensure that the organization's resources are allocated in a way that maximizes the protection of the organization's assets while supporting the organization's overall mission and objectives.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...