CISM Information Security Programme Practice Question
A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
⚠ Common exam trap
CISM often tests the risk-based vs. compliance-based mindset — candidates pick 'regulatory compliance only' because it sounds authoritative, but CISM emphasizes risk-driven prioritization that enables business operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize critical controls that address high-risk areas and enable business operations
A risk-based approach prioritizes controls that address the highest-risk areas while minimizing operational friction, which aligns security investment with business objectives. This ensures the greatest risk reduction per unit of effort and avoids disrupting critical business processes. It also reflects the CISM principle that security must enable the business, not obstruct it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement all controls from the chosen framework simultaneously
Why it's wrong here
Implementing every framework control at once ignores the stated goal of prioritising risk reduction against operational friction. Controls should be selected through a risk assessment that ranks them by exposure addressed and implementation cost, not adopted wholesale regardless of relevance or disruption.
- ✗
Implement compensating controls only for legacy systems
Why it's wrong here
Compensating controls address gaps where a primary control cannot be applied, typically on legacy systems. Restricting implementation to those alone leaves the wider control framework unaddressed, so the organisation gains no systematic risk reduction across its estate.
- ✓
Prioritize critical controls that address high-risk areas and enable business operations
Why this is correct
Prioritising critical controls addressing high-risk areas while enabling business operations targets the greatest risk reduction without imposing friction that blocks workflows. This satisfies the framework's dual constraint of maximum risk reduction and minimum operational friction, unlike blanket control deployment.
- ✗
Select controls based on regulatory compliance requirements only
Why it's wrong here
Basing selection solely on regulatory compliance addresses mandated baselines, not the risk-reduction-to-friction ratio the stem demands. Compliance controls may be costly yet leave material risks untreated. It is tempting because compliance is auditable and defensible, and it would be correct where the objective is achieving certification or satisfying a regulator's minimum requirements.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.