Courseiva

CISM Information Security Program Practice Question

A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?

⚠ Common exam trap

The trap here is jumping to control implementation or policy updates without first reassessing risks, which can lead to misaligned security investments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a new risk assessment that includes the cloud and telehealth environments.

The CISO should first perform a new risk assessment because significant changes such as cloud adoption, telehealth, and new regulations alter the risk landscape. A current risk assessment identifies new threats, vulnerabilities, and regulatory requirements, enabling the organization to update controls and policies effectively. This aligns with CISM's emphasis on continuous risk management as the core of an information security program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a security awareness campaign focused on telehealth and cloud security.

    Why it's wrong here

    Awareness campaigns address human behavior but do not replace the need for a comprehensive risk assessment. They are a control measure that should be deployed after risks are identified and prioritized. Focusing only on awareness may leave technical and process gaps unaddressed, and it does not ensure compliance with new regulations or the security of cloud and telehealth systems.

  • ✗

    Implement additional security controls for cloud and telehealth based on industry best practices.

    Why it's wrong here

    Implementing controls based on best practices without a risk assessment may address some risks but could also be misaligned with the organization's specific risk profile and business objectives. It might lead to unnecessary spending or leave other risks unaddressed. A risk assessment ensures that controls are prioritized and tailored to the actual threats and vulnerabilities.

  • ✓

    Perform a new risk assessment that includes the cloud and telehealth environments.

    Why this is correct

    A new risk assessment is the foundational step to identify and evaluate risks introduced by cloud services, telehealth, and regulatory changes. It provides the basis for updating security controls and strategies. Without a current risk assessment, any control adjustments would be based on outdated assumptions, potentially leaving critical gaps. CISM emphasizes that risk assessment should be ongoing and triggered by significant changes.

  • ✗

    Update the information security policy to include cloud and telehealth security requirements.

    Why it's wrong here

    Updating policy is important, but it should follow a risk assessment. Without understanding the new risks, policy changes may be incomplete or misdirected. Policies set the tone, but they must be informed by a current understanding of the risk environment. This step alone does not ensure that controls are effective or that regulatory requirements are met.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.