Courseiva

CISM Information Security Program Practice Question

A global financial services firm has a mature information security program with policies, standards, and procedures aligned to ISO/IEC 27001. The CISO is preparing for the annual management review of the program. The board has asked for assurance that the program remains effective as the threat landscape and business strategy evolve. Which activity BEST provides this assurance?

⚠ Common exam trap

The trap here is assuming that a technical activity such as penetration testing or awareness training alone constitutes sufficient evidence of program effectiveness for executive management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing the results of independent audits, control testing, and metrics against program objectives to evaluate effectiveness.

The board requires assurance that the program remains effective amid evolving threats and business strategy. Independent audits, control testing, and metrics provide objective, ongoing evidence of effectiveness across governance, risk, and controls. This integrated view supports informed management review and strategic decision-making, which is the core purpose of monitoring and reporting program performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increasing the security awareness training frequency and tracking completion rates across all business units.

    Why it's wrong here

    Awareness training addresses human risk and is a valuable control, but completion rates are an output metric, not an outcome measure of program effectiveness. This activity does not evaluate the full spectrum of security controls, risk treatment, or strategic alignment. It therefore cannot provide the comprehensive assurance the board seeks regarding the overall program.

  • ✗

    Conducting a penetration test of all externally facing applications and reporting the number of critical findings.

    Why it's wrong here

    Penetration testing is a point-in-time technical assessment of specific systems and does not evaluate the program's governance, risk management, or alignment with business strategy. It cannot demonstrate that policies, controls, and processes remain effective across the organization as threats and business objectives change. Reporting only critical findings further narrows the view, omitting program-level effectiveness.

  • ✓

    Reviewing the results of independent audits, control testing, and metrics against program objectives to evaluate effectiveness.

    Why this is correct

    This activity directly supports the management review requirement by consolidating independent assurance sources and performance metrics to evaluate whether the program meets its objectives. It considers governance, risk, and control effectiveness over time, providing the board with a holistic view. This aligns with CISM guidance on monitoring and reporting program effectiveness to stakeholders.

  • ✗

    Updating the information security policy to reflect the latest regulatory changes and obtaining executive sign-off.

    Why it's wrong here

    Updating policy is important for currency but is only one element of program governance. It does not measure whether existing controls are operating effectively or whether the program is achieving its objectives. Policy revision alone cannot provide assurance that the program remains effective against evolving threats or changing business strategy, so it is insufficient for the board's request.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.