CISM Information Security Programme Practice Question
A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?
⚠ Common exam trap
The trap here is assuming that more technical testing or raw incident statistics automatically constitute programme performance measurement for the board.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a set of programme performance metrics with targets and reporting frequency that map to the strategy's risk-reduction objectives.
The board approved a strategy and now wants assurance that it is producing the intended risk reduction between annual reviews. That requires a defined measurement framework linking programme performance to the strategy's objectives, with baselines, targets and a reporting cadence. Technical testing, budget requests and raw incident counts do not provide that ongoing, objective view of strategy delivery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Commission an external penetration test of the organisation's Internet-facing estate and report the findings to the board.
Why it's wrong here
A penetration test produces a point-in-time view of exploitable weaknesses and says nothing about whether the strategy's risk-reduction objectives are being met over time. It also measures only a narrow technical slice of the programme, so it cannot answer the board's question about ongoing delivery against the approved strategy.
- ✗
Request a budget increase for the next financial year so that additional controls can be deployed across the estate.
Why it's wrong here
Seeking more funding does not answer how the board will know the current strategy is working, and the board has already approved the strategy. Without a measurement framework the CISO cannot demonstrate whether existing spend is effective, so requesting more money first would appear unjustified and would not satisfy the governance question raised.
- ✗
Schedule quarterly presentations to the board summarising the number of security incidents detected by the security operations centre.
Why it's wrong here
Incident counts alone are a narrow operational statistic and can rise simply because detection improved, which makes them a poor proxy for strategy delivery. Quarterly briefings without defined objectives, baselines and targets give the board narrative rather than evidence, so this does not establish the measurement mechanism the board is asking for.
- ✓
Define a set of programme performance metrics with targets and reporting frequency that map to the strategy's risk-reduction objectives.
Why this is correct
The board needs a repeatable mechanism that shows progress against the objectives they approved. Establishing metrics with baselines, targets and a defined reporting cadence creates that feedback loop and lets the CISO demonstrate delivery between annual reviews, which is precisely what governance bodies require to exercise oversight of the security programme.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.