正解:C
The primary objective of creating a security culture is to reduce risk to acceptable levels (C) by influencing employee behavior and decision-making. CISM stresses that culture is a means to an end-not the end itself.
Prioritization (B), resource acquisition (A), and reporting (D) are outcomes or enablers, but the ultimate purpose is effective risk reduction aligned with business objectives. A strong security culture helps prevent incidents, improves compliance, and strengthens resilience through consistent, risk-aware behavior at all levels of the organization.
References: ISACA CISM Review Manual (Program management-security culture and behavior); CISM Exam Content Outline (Domain 3).