Courseiva

CISM Information Security Programme Practice Question

A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?

⚠ Common exam trap

CISM often tests the risk-based vs. compliance-based mindset — candidates pick 'regulatory compliance only' because it sounds authoritative, but CISM emphasizes risk-driven prioritization that enables business operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritize critical controls that address high-risk areas and enable business operations

A risk-based approach prioritizes controls that address the highest-risk areas while minimizing operational friction, which aligns security investment with business objectives. This ensures the greatest risk reduction per unit of effort and avoids disrupting critical business processes. It also reflects the CISM principle that security must enable the business, not obstruct it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement all controls from the chosen framework simultaneously

    Why it's wrong here

    Implementing every framework control at once ignores the stated goal of prioritising risk reduction against operational friction. Controls should be selected through a risk assessment that ranks them by exposure addressed and implementation cost, not adopted wholesale regardless of relevance or disruption.

  • ✗

    Implement compensating controls only for legacy systems

    Why it's wrong here

    Compensating controls address gaps where a primary control cannot be applied, typically on legacy systems. Restricting implementation to those alone leaves the wider control framework unaddressed, so the organisation gains no systematic risk reduction across its estate.

  • ✓

    Prioritize critical controls that address high-risk areas and enable business operations

    Why this is correct

    Prioritising critical controls addressing high-risk areas while enabling business operations targets the greatest risk reduction without imposing friction that blocks workflows. This satisfies the framework's dual constraint of maximum risk reduction and minimum operational friction, unlike blanket control deployment.

  • ✗

    Select controls based on regulatory compliance requirements only

    Why it's wrong here

    Basing selection solely on regulatory compliance addresses mandated baselines, not the risk-reduction-to-friction ratio the stem demands. Compliance controls may be costly yet leave material risks untreated. It is tempting because compliance is auditable and defensible, and it would be correct where the objective is achieving certification or satisfying a regulator's minimum requirements.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.