certslothcertsloth
CISM/Topic 06

ISACA / Professional

Security Strategy, Risk Ownership and Architecture

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Business sets the destination; security manages the risk on the route.

Must remember

Start with business objectives, obligations, critical processes and risk appetite. A security strategy defines desired outcomes and direction; a program turns that direction into initiatives, resources and operating processes. Buying a tool before understanding the risk can consume budget without reducing important exposure.

The governing body oversees direction and risk appetite; executives sponsor and fund; business owners own relevant business risks; security advises, coordinates and reports. Control owners operate controls. Formal risk acceptance belongs to authorized management, with documented rationale, scope and review date. A security manager should not silently accept a business exposure outside delegated authority.

Use asset ownership and classification to prioritize protection. Evaluate inherent risk before controls and residual risk after them, acknowledging uncertainty and control effectiveness. Reassess for new suppliers, business processes, threats and technology. A vulnerability score alone does not reveal business impact or decide investment priority.

Build a business case using expected risk reduction, compliance need, options, lifecycle cost and measurable outcomes. Enterprise architecture connects business capabilities, information, applications and technology; security architecture embeds trust boundaries and control patterns into that design. Trace a control to a requirement and a testable outcome. Policy states intent, standards specify required rules, procedures describe execution and guidelines recommend approaches.

Report in the audience’s terms: service disruption exposure, sensitive-data risk, risk acceptance and progress toward target capability. Avoid promising zero risk. Governance is effective when decisions and accountability work in practice, not merely when a committee exists.

Choose under exam pressure

Requirement Choice and reason
Choose the first security investment Assess business risk and existing gaps before selecting technology.
Residual risk exceeds tolerance Present options to the authorized risk owner/governance body.
New enterprise platform Embed security requirements and architecture patterns during design.

Traps

  • Security supports business objectives; the most restrictive control is not always the best fit.
  • A risk owner and a control operator are not necessarily the same person.

Active recall

1. Strategy versus program?

Direction and desired outcomes versus coordinated work/resources to realize them.

2. Who accepts residual business risk?

Authorized management or the designated risk owner, within governance limits.

3. Why connect architecture to controls?

To make security consistent with system boundaries, dependencies and business needs.

4. Why is a tool count a weak success metric?

It measures acquisition rather than control effectiveness or risk reduction.

5. What should a business case compare?

Options, costs, benefits, risk reduction and consequences of not acting.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.