Courseiva

CISM Information Security Programme Practice Question

A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?

⚠ Common exam trap

The trap here is assuming that technical tools or policy documents can substitute for executive-backed governance authority when a programme lacks a formal mandate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain executive and board approval for a formal information security charter that defines scope, authority, and accountability.

Establishing a formal, executive-approved charter gives the information security programme its mandate, scope, and enforcement authority. In this scenario, business units ignore the security team because it lacks organizational legitimacy, not because controls or policies are missing. A charter is the foundational governance artifact from which policy, risk assessment, and control deployment derive their authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an automated compliance scanning tool across all business units to identify policy deviations.

    Why it's wrong here

    Scanning tools detect technical deviations but do nothing to resolve the underlying governance problem: the security team has no approved mandate or authority, so findings can be ignored. Deploying tools before establishing a charter addresses symptoms rather than the root cause, and business units that already bypass security review are unlikely to accept scan-driven remediation without executive-backed authority.

  • ✗

    Develop a comprehensive set of security policies and distribute them to all department heads for immediate adoption.

    Why it's wrong here

    Policies issued without an approved charter lack organizational legitimacy and will likely be treated as suggestions rather than mandates. The scenario shows business units already bypass security review, so unbacked policies would face the same resistance. Policies should flow from an authorized programme charter that defines who can set them and how they are enforced.

  • ✗

    Conduct a full risk assessment of all critical business systems to quantify the current risk exposure.

    Why it's wrong here

    A risk assessment is valuable but premature before the programme has a formal mandate. The assessment results require an authoritative owner who can drive remediation, and without a charter the CISO cannot compel action on the findings. Establishing governance must precede assessment so that results feed into an accountable, executive-supported remediation process.

  • ✓

    Obtain executive and board approval for a formal information security charter that defines scope, authority, and accountability.

    Why this is correct

    A formally approved charter establishes the programme's mandate, scope, and authority, giving the CISO the organizational backing needed to enforce policy and require security review. Without this governance foundation, enforcement attempts lack legitimacy. It is the logical first step because every subsequent activity, including policy development and control implementation, depends on an authorized mandate from executive leadership.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.