(ISC)2 Certified in Cybersecurity Practice Exam

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the (ISC)2 Certified in Cybersecurity Exam with comprehensive quizzes and extensive question banks. Enhance your skills with detailed explanations and practice tests designed to improve your expertise for the certification exam. Get exam-ready now!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Why is proper alignment of security policy and business goals important?

  1. Security should always be as strict as possible

  2. Security policy that conflicts with business goals can inhibit productivity

  3. Bad security policy can be illegal

  4. Security is more important than business

The correct answer is: Security policy that conflicts with business goals can inhibit productivity

The importance of aligning security policy with business goals lies in the fact that when security measures are in conflict with the operational objectives of a business, they can significantly hinder productivity and efficiency. A well-structured security policy should not act as a barrier to the company's operations. Instead, it should support the business's strategies and objectives while simultaneously protecting its assets. When security policies are misaligned with business goals, it can result in excessive restrictions that may slow down processes, impede user experience, or prevent employees from performing their jobs effectively. For example, if a company implements stringent access controls that unnecessarily restrict employees from accessing essential tools or information, it can lead not only to frustration but also to significant delays in project timelines, negatively impacting overall performance. In contrast, an effective alignment ensures that security measures enhance business operations and are integrated into the organization's workflow. This alignment fosters a culture of security awareness while allowing the organization to operate more efficiently and effectively, ultimately aiding in achieving business objectives.