CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 475


Which of the following is the BEST indication that an information security program is aligned with organizational objectives?

Show Answer
Correct Answer: C

The best indication that an information security program is aligned with organizational objectives is when risk is managed to within organizational tolerances. This means the organization is taking into account its strategic goals and ensuring that the level of risk is acceptable within those parameters, directly reflecting the organization's priorities and objectives.

Discussion

2 comments
Sign in to comment
ChangwhaOption: C
Jul 21, 2023

C. Risk is managed to within organizational tolerances.

SwallowsOption: C
Jun 9, 2024

While having information security processes in place throughout the system development life cycle (SDLC) (option D) is important for building security into the organization's systems and applications, it may not necessarily guarantee alignment with organizational objectives. However, managing risk to within organizational tolerances directly reflects the organization's strategic priorities and ensures that the information security program is contributing to the achievement of those objectives. Therefore, option C is the BEST indication of alignment with organizational objectives.

Swallows
Jul 7, 2024

While senior management conducting regular reviews of information security policies (option A) is important for oversight and governance, it does not necessarily guarantee that security activities are aligned with organizational objectives in terms of risk management and strategic alignment.