Enterprise goals are the foundation for aligning security with business objectives. Policies must support and enable these goals to ensure the security function delivers business value and maintains stakeholder support. "Information security policies, standards, and procedures should be derived from and aligned with the enterprise's overall goals and objectives." - CISM Review Manual 15th Edition, Chapter 1: Governance of Information Security* Regulations and best practices help shape policy, but business alignment is paramount.