Information Security Program Alignment with Business Objectives | CISA Exam Answer

IS Auditor's Evidence of Information Security Program Alignment with Business Objectives

Prev Question Next Question

Question

Which of the following provides an IS auditor with the BEST evidence that an organization's information security program is aligned to business objectives?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

The best evidence that an organization's information security program is aligned with business objectives would be provided by the balanced scorecard.

The balanced scorecard is a strategic management tool that is used to align an organization's objectives with its strategies and measures its performance against those objectives. It provides a comprehensive and integrated view of an organization's performance by combining financial and non-financial measures, such as customer satisfaction, internal processes, and learning and growth.

An information security program that is aligned with the organization's business objectives should be reflected in the balanced scorecard. This is because the balanced scorecard includes measures that reflect the organization's overall strategic direction and priorities, which should include information security as a key component.

Risk assessment results, business impact analysis (BIA), and cost-benefit analysis are important tools in information security management, but they do not necessarily provide the best evidence that an organization's information security program is aligned with business objectives.

Risk assessment results provide information about the risks facing an organization, but they do not necessarily indicate whether the information security program is aligned with business objectives.

Business impact analysis (BIA) is a tool used to identify the potential impact of a disruption to an organization's business processes, but it does not necessarily indicate whether the information security program is aligned with business objectives.

Cost-benefit analysis is a tool used to evaluate the costs and benefits of a particular course of action, but it does not necessarily indicate whether the information security program is aligned with business objectives.

Therefore, the best evidence that an organization's information security program is aligned with business objectives would be provided by the balanced scorecard.