Courseiva

CISM Information Security Program Practice Question

A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?

⚠ Common exam trap

The trap here is assuming that adopting a framework or implementing a technical control immediately aligns security with business objectives, when alignment actually starts with understanding the business through risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a comprehensive risk assessment to identify and prioritize threats to business objectives.

The correct answer is to conduct a risk assessment first. This step identifies which business objectives are at risk and prioritizes threats, enabling the CISO to align security investments with what the business values most. It provides the evidence needed to justify budget allocation and ensures that subsequent security activities are driven by business needs rather than technology or compliance alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Develop a security awareness training program for all employees.

    Why it's wrong here

    Awareness training is important for reducing human risk, but it is a downstream control that should be implemented after risks are understood and prioritized. Initiating training first does not ensure alignment with business objectives because it does not identify which business processes or assets require protection. It also consumes resources that might be better allocated based on a risk-informed strategy.

  • ✗

    Adopt an industry-recognized framework such as ISO/IEC 27001 to structure the program.

    Why it's wrong here

    Frameworks provide structured approaches and best practices, but they are not a substitute for understanding the organization's specific business objectives and risk landscape. Adopting a framework first can lead to a compliance-driven program rather than a business-aligned one. The CISO should first assess risks to determine how the framework can be tailored to support business goals.

  • ✗

    Implement a security information and event management (SIEM) system to monitor for threats.

    Why it's wrong here

    A SIEM provides detection and monitoring capabilities, but deploying it before understanding business risks may lead to monitoring irrelevant data or missing critical assets. It is a technical control that should be selected based on identified risks and business needs. Starting with SIEM does not establish a clear link between security spending and business objectives, and could result in misaligned investments.

  • ✓

    Conduct a comprehensive risk assessment to identify and prioritize threats to business objectives.

    Why this is correct

    A risk assessment identifies which assets and processes are most critical to achieving business objectives, and prioritizes threats accordingly. This ensures that security investments are directly tied to protecting what matters most to the business. Without this foundational step, subsequent activities like policy development or control selection lack a business-driven rationale, making alignment difficult to demonstrate to the board.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.