正解:D
Risk tolerance levels (D) should be the primary basis for an information security business case because security investments are justified by their ability to reduce risk to levels acceptable to the organization.
CISM stresses that security exists to manage risk in alignment with business objectives and appetite. Budget (A), feasibility (B), and EA alignment (C) are important considerations, but they are secondary to demonstrating how a proposed initiative addresses risks that exceed tolerance. A strong business case clearly articulates the current risk exposure, the residual risk after implementation, and how the investment aligns with executive-defined tolerance thresholds. This approach directly supports informed decision-making by senior management.
References: ISACA CISM Review Manual (Program management-business cases, risk-based decision making); CISM Exam Content Outline (Domain 3).