Courseiva

CISM Information Security Programme Practice Question

A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?

⚠ Common exam trap

The trap here is scoping by an easily counted technical attribute such as location or user count instead of by the business impact the asset supports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The criticality of the business processes and information the assets support

Governance scope should be anchored to business criticality and information sensitivity, because that is where disruption, regulatory breach, or data loss would cause the greatest harm. Location, user population, and sourcing model are attributes that shape how controls are applied once an asset is in scope, but none of them reliably identifies which assets warrant programme governance in the first place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The physical location of the data center hosting each system

    Why it's wrong here

    Location matters for jurisdictional and resilience requirements, but it is a constraint on how controls are implemented, not the primary reason an asset enters scope. Scoping by geography would exclude critical cloud-hosted or outsourced services and include low-value systems that merely happen to sit in a covered facility, distorting governance priorities.

  • ✗

    The number of users who have accounts on each application

    Why it's wrong here

    User counts are a rough proxy for exposure but say nothing about the sensitivity of the data or the criticality of the process. A widely used scheduling tool may be low impact while a system used by three treasury staff moves millions. Scoping by population would misallocate governance attention and leave high-impact, low-user systems under-protected.

  • ✗

    Whether the system was purchased or developed in-house

    Why it's wrong here

    Build-versus-buy affects the control mechanisms available, such as vendor assurance versus secure development practices, but it does not determine whether the system belongs in the governance scope. A purchased core banking platform can be far more critical than an internally built utility, so this criterion would produce a scope misaligned with business risk.

  • ✓

    The criticality of the business processes and information the assets support

    Why this is correct

    Scope should follow business impact. Assets and processes that support critical services, hold sensitive data, or carry regulatory obligations define where governance, controls, and assurance effort must apply. Scoping by technical category or location instead produces coverage gaps precisely where the organization can least tolerate failure, which is the outcome the CISO must avoid.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.