CISM Information Security Program Practice Question
A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?
⚠ Common exam trap
The trap here is assuming that technical assessments or tool deployments should come first, when strategic alignment must precede tactical execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Translate the board's risk appetite into specific security requirements and objectives
The correct answer is to translate the board's risk appetite into specific security requirements and objectives. This step ensures the security program is aligned with business goals and provides a basis for resource allocation, prioritization, and measurement. It bridges the gap between high-level risk tolerance and operational security activities, enabling the CISO to build a program that effectively manages risk in line with the organization's strategic direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a comprehensive asset inventory and vulnerability assessment
Why it's wrong here
While asset inventory and vulnerability assessment are foundational, performing them before understanding the business context and risk appetite may lead to misaligned priorities. The CISO should first ensure the program is driven by business objectives, which requires translating the board's risk appetite into security requirements. Without that translation, technical assessments may focus on assets that are not critical to the business, wasting resources and failing to address the most significant risks.
- ✗
Purchase and deploy an advanced endpoint detection and response (EDR) solution
Why it's wrong here
Acquiring technology before defining requirements is a common pitfall. The CISO needs to understand the business objectives and risk appetite to determine if EDR is necessary and how it should be configured. Making a purchasing decision without this context could result in unnecessary expenditure or a solution that does not address the organization's specific risks. Strategy and requirements should always precede technology selection.
- ✓
Translate the board's risk appetite into specific security requirements and objectives
Why this is correct
The board's risk appetite statement provides the direction for the security program. Translating it into actionable security requirements and objectives ensures that security initiatives are directly linked to business goals and risk tolerance. This step is essential before allocating resources or conducting assessments, as it defines what the program must achieve. It also facilitates communication with stakeholders and helps justify budget requests by showing alignment with business strategy.
- ✗
Implement a security awareness training program for all employees
Why it's wrong here
Security awareness training is important but premature at this stage. Without a clear understanding of the risk appetite and business objectives, the training content may not address the most relevant risks. The CISO should first establish the strategic foundation by translating risk appetite into security requirements. Training is a tactical control that should be deployed after the program's scope and priorities are defined, ensuring it targets the right behaviors and risks.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.