Courseiva

CISM Information Security Program Practice Question

A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?

⚠ Common exam trap

The trap here is jumping to a technical enforcement or policy change without diagnosing the underlying reasons for non-compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a root cause analysis to determine why employees are not completing the training.

Conducting a root cause analysis is the essential first step. It identifies why employees are not completing the training, allowing the CISO to implement targeted and effective solutions. This approach is consistent with continuous improvement and ensures that resources are used efficiently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the non-compliance to the board of directors and request their intervention.

    Why it's wrong here

    Escalation to the board is premature without first investigating the cause. The board should be informed of significant issues, but the CISO should first gather facts and propose a remediation plan. Involving the board without analysis may undermine confidence in the security program.

  • ✗

    Revise the policy to extend the training deadline to 60 days to improve compliance.

    Why it's wrong here

    Changing the policy without understanding the cause may not solve the problem and could weaken the security posture. The original 30-day requirement may be appropriate; the issue is likely with the process or communication. The CISO should first investigate before altering policies.

  • ✗

    Implement a technical control that blocks network access for employees who have not completed training.

    Why it's wrong here

    A technical control may enforce compliance, but it is a drastic measure that can disrupt business operations. The first step should be to understand why employees are not completing the training. Blocking access without addressing root causes could harm productivity and morale.

  • ✓

    Conduct a root cause analysis to determine why employees are not completing the training.

    Why this is correct

    Before implementing solutions, the CISO must understand the reasons for non-compliance. Root cause analysis can reveal issues such as lack of awareness, inconvenient training times, or ineffective content. This ensures that the chosen remedy addresses the actual problem and is more likely to succeed.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.