CISM Information Security Governance Practice Question
A CISO is updating the organization's information security strategy to address emerging risks from cloud adoption and remote work. Which of the following should be the FIRST step in this process?
⚠ Common exam trap
The trap here is assuming that implementing a technical control or benchmarking is the starting point, when a risk assessment must precede any strategic changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a risk assessment to identify new threats and vulnerabilities.
The first step in updating the security strategy is to conduct a risk assessment, as it provides the necessary understanding of new risks introduced by cloud adoption and remote work. This risk-based approach ensures that subsequent decisions on controls, training, and investments are prioritized according to business impact and risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a cloud access security broker (CASB) solution.
Why it's wrong here
Implementing a CASB before assessing risks may lead to misaligned controls. The risk assessment should determine whether a CASB is needed and what capabilities are required. Jumping to a solution without understanding the specific risks can waste resources and fail to address the most critical exposures.
- ✗
Revise the security awareness training program.
Why it's wrong here
Updating training is important but not the first step. The risk assessment should identify whether awareness gaps are a significant risk. Without that understanding, training updates may not target the most relevant threats, such as phishing or insecure remote work practices.
- ✗
Benchmark the organization's security posture against industry peers.
Why it's wrong here
Benchmarking can provide useful context, but it is not the first step. The organization's unique risk profile and business objectives should drive the strategy. Benchmarking alone may lead to adopting controls that are not appropriate for the organization's specific circumstances.
- ✓
Conduct a risk assessment to identify new threats and vulnerabilities.
Why this is correct
The first step in updating the security strategy is to understand the current risk landscape through a risk assessment. This identifies threats, vulnerabilities, and potential business impacts related to cloud adoption and remote work. The results inform strategic priorities, resource allocation, and control selection, ensuring the strategy is risk-based and aligned with business objectives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.