You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
Start practicing
Information Security Programme — choose a session length
Free · No account required
Domain overview
This domain covers building, governing and operating the information security programme: strategy, frameworks, control prioritisation, budget justification, roles and awareness. Questions are scenario-based, asking you to pick the FIRST or BEST action for a security manager, weighing business alignment, risk, resource limits and defence-in-depth sequencing over technical tooling detail.
Exam objectives
Selecting control implementation groups and prioritising safeguards against ransomware exposure with limited resources
Applying defence-in-depth sequencing to framework adoption and control prioritisation decisions
Defining the purpose of a security champions programme in embedding security across business teams
Justifying security budget increases using risk reduction and business value metrics
Choosing the most technically complete control set instead of the FIRST priority given resource constraints and threat exposure.
Treating security champions as a technical escalation team rather than business-side advocates who extend the security function.
Justifying budget with fear, compliance mandates or incident anecdotes instead of quantified risk reduction and business alignment.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
2An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
3During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
4Which of the following is a LEADING indicator of security performance?
5An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
6A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
7Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?
8An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?
9What is the PRIMARY purpose of a security champions program?
10A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?
11A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?
12In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?
13An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?
14A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?
15A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?
16Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?
17An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?
18Which of the following is a leading indicator for security performance?
19A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?
20In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?
21A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?
22Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?
23A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?
24Which of the following is a key objective of a Security Operations Center (SOC)?
25An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?
26A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?
27Which TWO of the following are typical components of a security awareness program?
28Which of the following is a leading indicator of security program effectiveness?
29An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?
30A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?
31An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?
32Which control family in NIST SP 800-53 addresses the identification and authentication of users?
33In a security awareness program, which training approach is most appropriate for software developers?
34An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?
35A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?
36Which role is primarily responsible for designing and reviewing an organization's security architecture?
37An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?
38A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?
39Which THREE of the following are components of a security operations center (SOC)?
40Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?
41Which role is primarily responsible for developing and maintaining the organization's security architecture?
42Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?
43An organization is implementing a security champions program. What is the primary purpose of this initiative?
44When selecting security controls, a company must prioritize which controls first?
45A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?
46What is the primary function of a Security Operations Center (SOC)?
47Which TWO metrics are considered leading indicators for information security program performance?
48Which TWO are key elements of a security awareness program designed to change employee behavior?
49An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?
50A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
51An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?
52Which of the following best describes the role of a security architect in a security program?
53Which of the following is a key objective of implementing a security champions program?
54A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?
55A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?
56Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?
57What is the primary purpose of a vulnerability management program?
58An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?
59A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)
60Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)
61A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)
62Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?
63An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?
64A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?
65A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?
66During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?
67An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?
68Which of the following is the PRIMARY purpose of a security champions program?
69A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?
70An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)
71A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)
72When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?
73An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?
74A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?
75A security awareness manager is designing role-based training. Which training is most appropriate for software developers?
76In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?
77A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?
78An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?
79A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?
80A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?
81When designing phishing simulations, which approach best balances user learning and operational disruption?
82A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?
83Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)
84An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)
85A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)
86A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?
87A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?
88Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?
89An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?
90A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?
91An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?
92Which security team role is primarily responsible for defining and maintaining security architecture standards?
93An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?
94A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?
95When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?
96Which TWO of the following are components of a typical vulnerability management program?
97Which THREE of the following are key activities in a third-party risk management (TPRM) program?
98Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?
99In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?
100An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?
101A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?
102In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?
103Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?
104An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?
105Which of the following is the primary objective of a security champions programme?
106In a third-party risk management programme, what is the primary purpose of vendor tiering?
107During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?
108An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?
109A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)
110In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)
111Which of the following is the PRIMARY purpose of a security awareness program?
112An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?
113A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?
114An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?
115A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?
116A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?
117An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?
118Which of the following is the PRIMARY benefit of a security champions program?
119An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?
120A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?
121A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?
122A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?
123An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?
124A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?
125A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?
126An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?
127A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?
128An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?
129A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?
130A security architect is selecting controls for an e-commerce platform. Which TWO of the following are examples of compensating controls?
131An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
132A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?
133A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?
134A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?
135A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?
136A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?
137A financial services firm is updating its information security strategy and needs to align it with the organization's overall business goals. The CISO has been asked to ensure that the security strategy directly supports the achievement of business objectives. Which of the following should be the PRIMARY consideration when aligning the security strategy with business goals?
138A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?
139A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)
140A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)
141A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?
142A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?
143A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?
144A global manufacturing company has a decentralized information security program. Each region has its own security team and budget. The CISO is concerned about inconsistent security practices and wants to improve the program's maturity. Which of the following is the MOST effective approach to achieve consistency across regions while respecting local autonomy?
145A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?
146A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?
147A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?
148A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?
149A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?
150A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?
151A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?
152A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?
153A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?
154A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?
155A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?
156A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)
157A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?
158A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?
159A CISO is building the programme's risk treatment capability and wants to ensure that identified risks are handled consistently across business units. Which TWO activities are essential components of an effective risk treatment process? (Choose two.)
160An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.
161A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)
162An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?
163An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?
164A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?
165A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?
166During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?
167A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?
168A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?
169A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)
170A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)
171A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)
172A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)
173During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?
174A software company is defining the roles and responsibilities within its information security programme. The CISO wants clarity on who is accountable for ensuring that security requirements are integrated into the software development lifecycle. Which role should be assigned this accountability?
175A newly appointed CISO is reviewing the organization's information security policy framework. The board asks which document should define the organization's overall security objectives and assign responsibilities at the highest level. Which document is MOST appropriate for this purpose?
176During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?
You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
The Courseiva CISM question bank contains 176 questions in the Information Security Programme domain, covering the 17% of the exam attributed to this domain in the official ISACA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Information Security Programme domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included