The primary objective of a cyber resilience strategy is business continuity (B). In CISM, cyber resilience is defined as the organization’s ability to prepare for, respond to, recover from, and adapt to adverse cyber events while continuing to deliver critical business services. The focus is not on preventing all incidents—which is unrealistic—but on ensuring that essential operations can continue or be restored within acceptable timeframes despite cyber disruptions.
Employee awareness (A) and executive support (C) are important enablers of resilience, but they are means, not the ultimate objective. Regulatory compliance (D) is a governance requirement, but compliance alone does not guarantee operational resilience. CISM emphasizes that resilience strategies are driven by business impact analysis (BIA) results, recovery objectives, and tolerance for disruption, all of which directly support continuity of critical services.
A cyber resilience strategy integrates incident response, disaster recovery, backup, redundancy, and crisis management to minimize operational impact. Therefore, ensuring business continuity and operational resilience is the core objective against which cyber resilience effectiveness is measured.
[References:, ISACA CISM Review Manual, Information Security Program Development and Management — cyber resilience and business continuity, ISACA CISM Exam Content Outline, Domain 3: Information Security Program Development and Management, , , , ]
Submit