Courseiva
Question 331 of 871
Information Security ProgrameasyMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

A small business is developing its first information security program. Which approach is most effective?

⚠ Common exam trap

Watch out — candidates often confuse 'security tools' or 'frameworks' with 'program development,' mistakenly believing that deploying a specific technology or adopting a standard immediately constitutes an effective security program, when in fact the CISM exam requires that risk assessment must precede any control selection or framework adoption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a risk assessment to identify key assets and threats.

Conducting a risk assessment (Option C) is the foundational step in building an information security program because it identifies the specific assets, threats, vulnerabilities, and impacts unique to the small business. Without this context, any controls or frameworks applied would be misaligned with the actual risk profile, leading to wasted resources and potential security gaps. The CISM framework emphasizes that risk assessment drives the selection of cost-effective, prioritized controls tailored to the organization's needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Hire an external security consultant to design the entire program.

    Why it's wrong here

    Not sustainable; lacks internal ownership and continuous improvement.

  • Adopt a comprehensive framework like ISO 27001 immediately.

    Why it's wrong here

    Too complex and costly for initial stage; may not address specific risks.

  • Conduct a risk assessment to identify key assets and threats.

    Why this is correct

    Aligns program with actual business risks and priorities.

  • Purchase and deploy a next-generation firewall.

    Why it's wrong here

    A point solution, not a program; no governance or risk management.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.