Courseiva

CISM Information Security Programme Practice Question

A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?

⚠ Common exam trap

The trap here is choosing a decisive-sounding action such as a global policy mandate or tool purchase when the programme first needs an evidence-based baseline against the chosen framework.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a gap assessment of current regional practices against the chosen framework

Comparability across regions requires a common reference framework plus a factual baseline of where each region stands against it. A gap assessment delivers both, giving the CISO evidence to prioritize remediation, allocate budget, and report progress to the board. Mandating uniform policy, buying tooling, or auditing everything at once all presume knowledge the CISO does not yet have and skip the diagnostic step that makes the board's comparison meaningful.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mandate that all regions immediately adopt the headquarters policy set unchanged

    Why it's wrong here

    Immediate top-down adoption ignores regulatory, contractual, and cultural differences across regions and typically triggers resistance or silent non-compliance. It also skips the diagnostic step, so the CISO cannot demonstrate which gaps mattered most or measure improvement. The board asked for comparability, which requires a measured baseline, not a decree that erases the evidence needed to compare regions.

  • ✓

    Perform a gap assessment of current regional practices against the chosen framework

    Why this is correct

    Before harmonizing anything, the CISO must know where each region stands relative to the target framework. A structured gap assessment produces the factual baseline that prioritization, sequencing, and board reporting all depend on. Jumping to remediation without that baseline risks funding the wrong regions and leaves no defensible measure of progress for the board's comparison objective.

  • ✗

    Procure an integrated GRC platform to consolidate all regional risk registers

    Why it's wrong here

    A tool consolidates data but does not define the target state, the assessment criteria, or the remediation sequence. Buying a platform before understanding regional gaps often locks in inconsistent data models and creates expensive rework. The board's request is about comparability against a standard, which is a process and governance problem before it is a technology problem.

  • ✗

    Commission an external audit of every regional security control simultaneously

    Why it's wrong here

    A simultaneous full audit is costly, disruptive, and produces findings without a framework-aligned structure for prioritization. It also front-loads assurance before the CISO has defined the target standard, so results may not be comparable across regions. A gap assessment is the lighter, framework-anchored first step that informs whether and where deeper audits are warranted.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.