CISM Information Security Risk Management Practice Question
A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?
⚠ Common exam trap
The trap here is jumping to a visible technical or legal action instead of first measuring the organization’s current state against the new legal requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a gap analysis between the law’s requirements and the current security controls.
The first step in achieving compliance is to understand the difference between what the law requires and what the organization currently does. A gap analysis produces that understanding by mapping requirements to existing controls, identifying deficiencies and highlighting areas where evidence is missing. This allows the CISO to prioritize remediation, allocate budget and build a realistic compliance plan before making technical or policy changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Engage external legal counsel to interpret the law’s requirements.
Why it's wrong here
Legal interpretation is valuable and often necessary, but it is an input to the gap analysis, not a substitute for it. Counsel can clarify obligations, yet the CISO still must compare those obligations against the organization’s actual controls. Starting with legal review alone would not reveal the specific technical and procedural shortfalls that the security program needs to remediate.
- ✗
Implement encryption for all data at rest and in transit across the enterprise.
Why it's wrong here
Encryption may be one requirement of the law, but implementing it broadly before identifying which data and systems are in scope could waste resources and still leave other mandated controls unaddressed. The CISO first needs a gap analysis to know whether encryption is required, for what data, and what other obligations exist. Jumping to a technical control skips the essential assessment step.
- ✓
Conduct a gap analysis between the law’s requirements and the current security controls.
Why this is correct
A gap analysis is the logical first step because it identifies where the current program falls short of the legal requirements. Without understanding the gaps, the CISO cannot prioritize investments, assign resources or develop a credible compliance roadmap. The analysis provides the factual basis for all subsequent decisions, ensuring that remediation efforts target actual deficiencies rather than assumptions.
- ✗
Update the information security policy to reference the new law.
Why it's wrong here
Policy updates are important for governance, but revising policy before understanding the gaps can produce aspirational statements that the organization cannot yet meet. The CISO should first determine where controls fall short, then update policies to reflect achievable and required practices. Policy change without a gap analysis risks creating unenforceable requirements and misleading stakeholders about compliance readiness.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.