CISM Information Security Program Practice Question
A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?
⚠ Common exam trap
The trap here is assuming that updating the security strategy or implementing controls should come first, but without a risk assessment, these actions may not address the actual risks of the merger.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a security risk assessment of the target company's environment.
The correct answer is to conduct a security risk assessment of the target company's environment. This step is foundational because it identifies risks that must be managed during the merger. It enables the CISO to provide the board with a clear picture of the security landscape, ensuring that subsequent actions such as strategy updates or control implementations are based on actual risks rather than assumptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the information security strategy to include merger integration goals.
Why it's wrong here
Updating the strategy is important but premature without first understanding the risks. The CISO needs data from a risk assessment to tailor the strategy effectively. Without assessing the target's security posture, the strategy may not address actual integration challenges, leading to misalignment with business goals.
- ✓
Conduct a security risk assessment of the target company's environment.
Why this is correct
This is correct because a security risk assessment of the target company identifies vulnerabilities, control gaps, and potential threats that could affect the merged entity. It provides the board with the necessary information to make informed decisions about integration and risk mitigation, aligning security with the business objective of a successful merger.
- ✗
Implement security controls from the acquiring company on the target's systems.
Why it's wrong here
Implementing controls before assessing the target's environment could disrupt operations and may not address the most critical risks. It also assumes the acquiring company's controls are sufficient, which may not be true. A risk-based approach should precede control implementation to ensure resources are allocated effectively.
- ✗
Develop a security integration plan for post-merger activities.
Why it's wrong here
A security integration plan is necessary but should be based on the findings of a risk assessment. Developing the plan first without understanding the target's risks could lead to ineffective integration and missed vulnerabilities. The plan must be informed by a thorough assessment to align with business objectives.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.