Courseiva

CISM Information Security Program Practice Question

A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?

⚠ Common exam trap

The trap here is assuming that technical assessments or tool deployments should come first, when strategic alignment must precede tactical execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Translate the board's risk appetite into specific security requirements and objectives

The correct answer is to translate the board's risk appetite into specific security requirements and objectives. This step ensures the security program is aligned with business goals and provides a basis for resource allocation, prioritization, and measurement. It bridges the gap between high-level risk tolerance and operational security activities, enabling the CISO to build a program that effectively manages risk in line with the organization's strategic direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a comprehensive asset inventory and vulnerability assessment

    Why it's wrong here

    While asset inventory and vulnerability assessment are foundational, performing them before understanding the business context and risk appetite may lead to misaligned priorities. The CISO should first ensure the program is driven by business objectives, which requires translating the board's risk appetite into security requirements. Without that translation, technical assessments may focus on assets that are not critical to the business, wasting resources and failing to address the most significant risks.

  • ✗

    Purchase and deploy an advanced endpoint detection and response (EDR) solution

    Why it's wrong here

    Acquiring technology before defining requirements is a common pitfall. The CISO needs to understand the business objectives and risk appetite to determine if EDR is necessary and how it should be configured. Making a purchasing decision without this context could result in unnecessary expenditure or a solution that does not address the organization's specific risks. Strategy and requirements should always precede technology selection.

  • ✓

    Translate the board's risk appetite into specific security requirements and objectives

    Why this is correct

    The board's risk appetite statement provides the direction for the security program. Translating it into actionable security requirements and objectives ensures that security initiatives are directly linked to business goals and risk tolerance. This step is essential before allocating resources or conducting assessments, as it defines what the program must achieve. It also facilitates communication with stakeholders and helps justify budget requests by showing alignment with business strategy.

  • ✗

    Implement a security awareness training program for all employees

    Why it's wrong here

    Security awareness training is important but premature at this stage. Without a clear understanding of the risk appetite and business objectives, the training content may not address the most relevant risks. The CISO should first establish the strategic foundation by translating risk appetite into security requirements. Training is a tactical control that should be deployed after the program's scope and priorities are defined, ensuring it targets the right behaviors and risks.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.