CISM Information Security Program Practice Question
A newly appointed CISO is reviewing the existing information security program. The program has many documented policies and procedures, but the CISO notices that they have not been updated in over three years. What should the CISO do FIRST?
⚠ Common exam trap
The trap here is assuming that updating all policies immediately or delegating without analysis is efficient, when a gap analysis is needed to prioritize and justify changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a gap analysis to determine which policies are outdated and need revision.
The correct answer is to conduct a gap analysis first. This step identifies which policies are outdated or missing, allowing the CISO to prioritize updates based on risk and business impact. It ensures that subsequent efforts are targeted and justified, rather than a blanket rewrite that could waste resources and still miss critical issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Schedule a management review to approve the existing policies as they are.
Why it's wrong here
Approving outdated policies without review perpetuates potential misalignment with current threats, regulations, and business objectives. It also fails to address the CISO's concern about the lack of updates. Management review should occur after revisions are made, not to rubber-stamp stale documents.
- ✗
Immediately rewrite all policies to reflect current best practices.
Why it's wrong here
Rewriting all policies without analysis is inefficient and may not address the most critical gaps. It could also introduce inconsistencies or unnecessary changes. A targeted approach based on a gap analysis is more resource-effective and ensures that updates are driven by risk and business requirements, not just a desire for freshness.
- ✗
Delegate the policy update task to the security team without further direction.
Why it's wrong here
Delegating without direction risks inconsistent updates that may not align with business strategy or risk priorities. The CISO should first understand the gaps and provide guidance on priorities. This ensures that the team focuses on the most critical policies and that updates are coherent and aligned with the program's objectives.
- ✓
Conduct a gap analysis to determine which policies are outdated and need revision.
Why this is correct
A gap analysis will systematically identify which policies are outdated, missing, or misaligned with current business needs and risks. This provides a prioritized list for updates and ensures that revisions are based on actual deficiencies rather than assumptions. It is the logical first step to bring the program up to date efficiently and effectively.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.