Courseiva

CISM Information Security Programme Practice Question

A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)

⚠ Common exam trap

The trap here is treating visible hands-on security tasks as management functions simply because they are important to the programme's success.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defining and maintaining the security strategy aligned with enterprise business objectives.

Core programme management functions involve setting direction and securing the means to execute: strategy definition and resource management such as budget and staffing. Operational activities including scanning, SOC monitoring, and firewall administration are delivery tasks that management oversees and funds but does not perform. Separating these layers keeps governance focused and accountability clear.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Monitoring security information and event management alerts in the security operations centre.

    Why it's wrong here

    Alert monitoring in the SOC is a real-time operational activity, typically staffed 24x7 by analysts. It is delivery, not programme management. The management layer decides SOC staffing levels, service levels, and escalation paths, but does not itself monitor alerts. Confusing the two leads to governance gaps because nobody is left to oversee whether the SOC is effective.

  • ✗

    Administering firewall rule changes and maintaining network access control lists.

    Why it's wrong here

    Firewall rule administration and ACL maintenance are hands-on technical operations performed by network or security operations staff under change control. These are delivery tasks governed by policy and standards, not management functions. Treating them as management activities would blur accountability and distract leadership from setting direction, measuring performance, and securing resources.

  • ✗

    Performing vulnerability scans and tracking remediation of identified technical weaknesses.

    Why it's wrong here

    Vulnerability scanning and remediation tracking are operational security delivery activities performed by security engineers and system owners. While management sets the policy and cadence for scanning, executing scans and chasing patches is execution work. Classifying this as a core management function would misallocate the CISO's attention away from strategy, governance, and resourcing.

  • ✓

    Defining and maintaining the security strategy aligned with enterprise business objectives.

    Why this is correct

    Strategy definition is a core programme management function because it sets direction, scope, and investment priorities for the entire security effort. It requires translating business goals into security objectives and is owned by the CISO, not by operational teams. Without it, operational activities lack coherence and cannot be measured against enterprise intent, making it a fundamental management responsibility.

  • ✓

    Managing the security budget, staffing model, and resource allocation across the programme.

    Why this is correct

    Budget, staffing, and resource allocation are management functions that determine whether the programme can execute its strategy. The CISO must balance funding across prevention, detection, and response capabilities and justify investments to executives. These decisions are distinct from hands-on security work and are essential to running the programme as a managed business function.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.