CISM Information Security Program Practice Question
A mid-sized financial services firm has a newly appointed CISO. The board has asked for assurance that the information security program aligns with the organization's strategic goals and risk appetite. The CISO needs to establish a governance structure that provides ongoing oversight and ensures security decisions are made at the right level. Which of the following should the CISO implement FIRST?
⚠ Common exam trap
The trap here is focusing on tactical security activities like penetration testing or training instead of recognizing that the board's request for strategic alignment and oversight requires a governance structure first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security steering committee composed of senior business and IT leaders that meets regularly to review security strategy, risk, and performance.
Establishing a security steering committee with senior business and IT leaders is the foundational governance step. It creates a direct link between the security program and business strategy, ensures security decisions are made at the appropriate level, and provides ongoing oversight. This structure enables the CISO to align security initiatives with the organization's risk appetite and gives the board the assurance they are seeking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A security steering committee composed of senior business and IT leaders that meets regularly to review security strategy, risk, and performance.
Why this is correct
A security steering committee with senior business and IT leaders provides the necessary governance linkage between the security program and business strategy. It ensures that security decisions consider business objectives and risk appetite, and it gives the CISO a forum to report on program performance and escalate issues. This structure directly addresses the board's request for assurance and ongoing oversight, making it the foundational first step.
- ✗
A comprehensive penetration test of all external-facing applications to identify vulnerabilities.
Why it's wrong here
While penetration testing is valuable for identifying technical vulnerabilities, it does not establish governance or align the security program with business goals. The board is asking for assurance of strategic alignment and oversight, not a point-in-time technical assessment. Conducting a penetration test first would address tactical security gaps but leave the governance and alignment question unanswered, so it is not the best first step.
- ✗
A detailed security awareness training program for all employees to reduce human risk.
Why it's wrong here
Security awareness training is an important control for reducing human-related risk, but it is an operational activity, not a governance mechanism. The board's request focuses on strategic alignment and oversight, which require a governance structure. Implementing training first would not provide the board with the assurance they seek regarding program alignment and decision-making at the right level.
- ✗
A new security incident response plan that defines roles and responsibilities for handling breaches.
Why it's wrong here
An incident response plan is essential for managing security incidents, but it is a component of the security program, not the governance framework itself. The board's request is about strategic alignment and ongoing oversight, which are governance concerns. Developing an incident response plan first would not establish the necessary governance structure or ensure that security decisions align with business objectives and risk appetite.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.