CISM Information Security Program Practice Question
A small e-commerce company with 50 employees and limited IT budget is establishing its first formal information security program. The company processes customer payment data and must comply with PCI DSS. The CEO wants to balance security with operational costs. The IT manager proposes investing in a state-of-the-art security information and event management (SIEM) system costing $100,000 annually. The CISO, however, recommends a more phased approach. Considering the company's size, budget constraints, and compliance requirements, what should be the CISO's primary recommendation?
⚠ Common exam trap
CISM often tests the temptation to pick the most technically advanced control (SIEM) when the scenario emphasizes budget and maturity — the correct answer is almost always the risk-proportionate, foundational control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a firewall, antivirus software, and enforce strong access controls as baseline security measures.
For a 50-person e-commerce company with limited budget and PCI DSS obligations, the CISO should recommend foundational controls first: firewall, antivirus/endpoint protection, and strong access controls. These address the PCI DSS baseline requirements (Req 1, 5, 7, 8) at a fraction of the SIEM cost and deliver immediate risk reduction. A phased approach aligns security investment with maturity and budget, which is the core of the CISO's recommendation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement the SIEM system immediately to achieve real-time threat detection.
Why it's wrong here
A $100,000 annual SIEM consumes most of a 50-employee firm's security budget, leaving no funding for PCI DSS-required controls such as segmentation, encryption or access reviews. SIEM suits mature programs with staffed 24/7 monitoring and log volume justifying correlation.
- ✗
Outsource all security operations to a managed security service provider (MSSP).
Why it's wrong here
Full outsourcing hands payment-card processing oversight to a third party, yet PCI DSS accountability remains with the company, and MSSP contracts rarely cover the specific controls required. MSSPs suit organisations lacking any internal security capability and willing to fund continuous retainers.
- ✗
Develop a custom security software solution tailored to the company's payment processing system.
Why it's wrong here
Custom software development diverts limited budget into building tooling that commercial products already provide, delaying PCI DSS compliance without reducing assessed risk. Bespoke security tooling suits organisations with unique, unmet requirements and dedicated development resources.
- ✓
Deploy a firewall, antivirus software, and enforce strong access controls as baseline security measures.
Why this is correct
Deploying a firewall, antivirus and strong access controls directly satisfies PCI DSS's foundational requirements while remaining affordable for a 50-employee firm with limited budget. These controls address the realistic threat surface of a small e-commerce operation, unlike a $100,000 SIEM whose monitoring complexity exceeds the company's staffing capacity.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.