CISM Information Security Governance Practice Question
A healthcare organization is developing an information security governance framework. The CISO needs to ensure that the framework supports regulatory compliance with HIPAA and aligns with the organization's strategic goals. Which of the following should be the FIRST step in this process?
⚠ Common exam trap
The trap here is jumping to implementation activities like gap assessments or tool selection before defining what the governance framework is supposed to achieve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define the scope and objectives of the governance framework.
The first step in developing a governance framework is to define its scope and objectives. This ensures that the framework is aligned with business strategy and regulatory requirements, such as HIPAA. It provides a clear direction for subsequent activities, including risk assessments, policy development, and control implementation. Without this foundational step, efforts may be unfocused and fail to meet stakeholder needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define the scope and objectives of the governance framework.
Why this is correct
Defining the scope and objectives is the essential first step in developing any governance framework. It clarifies what the framework will cover, its boundaries, and what it aims to achieve, ensuring alignment with business strategy and regulatory requirements. Without this, efforts may lack direction and fail to address key stakeholder needs. This step sets the foundation for all subsequent activities.
- ✗
Conduct a gap assessment against the HIPAA Security Rule.
Why it's wrong here
A gap assessment is valuable for identifying current compliance status, but it is not the first step in establishing a governance framework. The framework's scope and objectives must be defined first to ensure the gap assessment is properly targeted. Without clear objectives, the assessment may be too broad or miss critical areas. The gap assessment is a subsequent activity that informs the framework's development.
- ✗
Develop a security awareness program for all staff.
Why it's wrong here
Security awareness is an important component of a security program, but it is not the first step in establishing governance. Awareness activities should be driven by policies and procedures that are part of the governance framework. Without a defined framework, awareness efforts may lack focus and not address the most critical risks. Governance structure and objectives must be established first.
- ✗
Select and implement a governance, risk, and compliance (GRC) tool.
Why it's wrong here
A GRC tool is an enabler, not the starting point. Implementing a tool before defining scope and objectives can lead to misalignment with actual needs and wasted resources. The tool should support the framework, but the framework's design must come first. The CISO should first determine what the governance framework should achieve and then consider technology to support it.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.