CISM Information Security Risk Management Practice Question
A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?
⚠ Common exam trap
It's easy for candidates to confuse budget justification artifacts, such as peer benchmarks or tool inventories, with evidence of compliance alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.
A gap assessment that maps controls to regulatory requirements and prioritizes remediation by risk directly demonstrates alignment between the security program and compliance obligations. It gives executives a clear view of exposure and a plan for closure. Tool inventories, commitment statements, and peer benchmarks lack the requirement-to-control mapping needed for a risk-based implementation plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A gap assessment mapping current controls to each regulatory requirement with prioritized remediation based on risk.
Why this is correct
A gap assessment maps existing controls to regulatory requirements and prioritizes remediation by risk, showing executives exactly where exposure exists and how it will be addressed. This aligns security investment with compliance obligations and provides a defensible, measurable plan. It demonstrates that the program is driven by both regulatory need and business risk rather than by technology preferences.
- ✗
A benchmark comparison showing that peer companies spend more on security.
Why it's wrong here
Peer spending comparisons do not demonstrate compliance with the specific regulation or identify the organization's own gaps. Spending levels vary with business model, risk profile, and scope, so they are poor proxies for adequacy. This approach may justify budget but does not show alignment between the security program and regulatory obligations.
- ✗
A list of all security tools currently deployed with their license costs.
Why it's wrong here
A tool inventory with costs does not show whether controls satisfy the new regulation or where gaps remain. Executives need to understand compliance exposure and remediation priorities, not just current spending. This artifact lacks the mapping between requirements, controls, and risk that demonstrates alignment with obligations.
- ✗
A statement that the organization will comply with the regulation by the deadline.
Why it's wrong here
A commitment statement without supporting analysis provides no evidence of how compliance will be achieved or where risk remains. It does not help the executive committee allocate resources or track progress. Alignment requires a structured assessment of requirements against current capabilities and a risk-based plan for closing gaps.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.