CISM Information Security Programme Practice Question
A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?
⚠ Common exam trap
Many exam-takers confuse post-deployment testing or awareness activities with true SDLC integration, which requires a defined process gate and documented risk assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a security risk assessment as a gate in the system development life cycle (SDLC).
Integrating security into the SDLC through a formal risk assessment gate ensures that security requirements are considered at the right time, with accountability and documentation. It transforms security from an afterthought into a standard project step, enabling consistent risk-based decisions. The other activities are valuable but do not create the structured, repeatable integration the CISO is seeking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require a security risk assessment as a gate in the system development life cycle (SDLC).
Why this is correct
Embedding a security risk assessment as a formal gate in the SDLC ensures that security requirements are identified, evaluated, and addressed before projects proceed. This integrates security into project workflows rather than adding it after deployment. It also creates consistent, auditable evidence of due diligence. The other options are either reactive, incomplete, or address only part of the problem, making them less effective for systematic integration.
- ✗
Deploy a vulnerability scanner across the development environment.
Why it's wrong here
A vulnerability scanner can identify technical weaknesses in code or configurations, but it does not establish a process for capturing and addressing security requirements during design and development. Scanning is a detection activity that supports later stages; it does not ensure that security is considered at project initiation or that requirements are formally integrated.
- ✗
Create a security awareness campaign for project managers.
Why it's wrong here
Awareness training can improve understanding but does not enforce or verify that security requirements are incorporated into projects. Without a defined process, gate, or accountability mechanism, integration remains optional and inconsistent. Awareness is a supporting activity, not a control that ensures security is built into the SDLC.
- ✗
Perform an annual penetration test on all production systems.
Why it's wrong here
Annual penetration testing is a point-in-time validation of existing controls and does not integrate security requirements into new projects. It occurs after systems are built, so it cannot prevent design flaws or missing controls. While useful for assurance, it fails to address the CISO's goal of embedding security into every new IT project from the start.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.