Exam CISM Topic 1 Question 255 Discussion

Actual exam question for ISACA's CISM exam
Question #: 255
Topic #: 1
Which of the following attributes is MOST important to consider when planning to adopt a recognized standard or framework for information security?

Suggested Answer: B Vote an answer

The correct answer is B because the most important consideration when adopting a recognized information security standard or framework is whether it applies to the organization's specific needs. A framework should support the organization's business objectives, risk profile, regulatory obligations, industry context, technology environment, operating model, maturity level, and stakeholder expectations. Ease of implementation is useful, but a framework that is easy to implement may not address the organization's most important risks. The ability to measure and compare can help with benchmarking and maturity assessment, but it is secondary to relevance. Cost-benefit is important for planning and prioritization, but cost alone should not drive framework selection if the framework is not suitable. CISM governance principles emphasize alignment with enterprise objectives and risk-based security management. A recognized standard or framework should be adopted because it helps the organization manage relevant information security risks effectively. Therefore, applicability to organizational needs is the most important attribute.
Reference: CISM Information Security Governance; framework adoption, business alignment, information security strategy, and risk-based governance principles.

by Clementine at Sep 30, 2026, 10:15 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10