CISM Information Security Program Practice Question
A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?
⚠ Common exam trap
The trap here is that candidates often jump to 'implement compensating controls' (Option D) as a quick fix, but CISM emphasizes that the first step must always be to understand the failure through root cause analysis before selecting any corrective action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a root cause analysis to determine why controls failed.
When controls are found ineffective, the security manager must first conduct a root cause analysis to identify why the controls failed. This aligns with the CISM's emphasis on corrective action based on understanding the underlying failure, such as misconfigured firewall rules, outdated signature databases, or improper access control lists (ACLs). Without this analysis, any subsequent remediation (like implementing compensating controls or increasing testing frequency) may address symptoms rather than the actual cause, leading to recurring failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a root cause analysis to determine why controls failed.
Why this is correct
Root cause analysis identifies why the controls failed before remediation, satisfying the need to address underlying deficiencies rather than symptoms. Auditors expect corrective action to be risk-based; understanding causation lets the security manager reassess the risk assessment and prioritise fixes, preventing recurrence across the control set.
- ✗
Increase the frequency of control testing.
Why it's wrong here
Testing frequency detects control failures; it does not remediate the ineffective controls already found. Raising frequency is correct for validating controls with high drift or weak monitoring, not as the first action after an audit has confirmed ineffectiveness.
- ✗
Report the findings to management and accept the risk.
Why it's wrong here
Accepting risk is a management decision made after remediation options and residual exposure are analysed, not the immediate step. Reporting and acceptance suit risks that cannot be cost-effectively mitigated, following assessment of the failed controls' impact.
- ✗
Implement compensating controls immediately.
Why it's wrong here
Compensating controls address residual risk after the gap is understood and accepted; deploying them immediately skips root-cause analysis and risk re-assessment. They are the right response once a primary control cannot be remediated within the required timeframe.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.