Courseiva

CISM Information Security Risk Management Practice Question

A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?

⚠ Common exam trap

It's easy for candidates to confuse budget justification artifacts, such as peer benchmarks or tool inventories, with evidence of compliance alignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.

A gap assessment that maps controls to regulatory requirements and prioritizes remediation by risk directly demonstrates alignment between the security program and compliance obligations. It gives executives a clear view of exposure and a plan for closure. Tool inventories, commitment statements, and peer benchmarks lack the requirement-to-control mapping needed for a risk-based implementation plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.

    Why this is correct

    A gap assessment maps existing controls to regulatory requirements and prioritizes remediation by risk, showing executives exactly where exposure exists and how it will be addressed. This aligns security investment with compliance obligations and provides a defensible, measurable plan. It demonstrates that the program is driven by both regulatory need and business risk rather than by technology preferences.

  • ✗

    A benchmark comparison showing that peer companies spend more on security.

    Why it's wrong here

    Peer spending comparisons do not demonstrate compliance with the specific regulation or identify the organization's own gaps. Spending levels vary with business model, risk profile, and scope, so they are poor proxies for adequacy. This approach may justify budget but does not show alignment between the security program and regulatory obligations.

  • ✗

    A list of all security tools currently deployed with their license costs.

    Why it's wrong here

    A tool inventory with costs does not show whether controls satisfy the new regulation or where gaps remain. Executives need to understand compliance exposure and remediation priorities, not just current spending. This artifact lacks the mapping between requirements, controls, and risk that demonstrates alignment with obligations.

  • ✗

    A statement that the organization will comply with the regulation by the deadline.

    Why it's wrong here

    A commitment statement without supporting analysis provides no evidence of how compliance will be achieved or where risk remains. It does not help the executive committee allocate resources or track progress. Alignment requires a structured assessment of requirements against current capabilities and a risk-based plan for closing gaps.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.