Courseiva

CISM Information Security Risk Management Practice Question

A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?

⚠ Common exam trap

The trap here is jumping to a visible technical or legal action instead of first measuring the organization’s current state against the new legal requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a gap analysis between the law’s requirements and the current security controls.

The first step in achieving compliance is to understand the difference between what the law requires and what the organization currently does. A gap analysis produces that understanding by mapping requirements to existing controls, identifying deficiencies and highlighting areas where evidence is missing. This allows the CISO to prioritize remediation, allocate budget and build a realistic compliance plan before making technical or policy changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Engage external legal counsel to interpret the law’s requirements.

    Why it's wrong here

    Legal interpretation is valuable and often necessary, but it is an input to the gap analysis, not a substitute for it. Counsel can clarify obligations, yet the CISO still must compare those obligations against the organization’s actual controls. Starting with legal review alone would not reveal the specific technical and procedural shortfalls that the security program needs to remediate.

  • ✗

    Implement encryption for all data at rest and in transit across the enterprise.

    Why it's wrong here

    Encryption may be one requirement of the law, but implementing it broadly before identifying which data and systems are in scope could waste resources and still leave other mandated controls unaddressed. The CISO first needs a gap analysis to know whether encryption is required, for what data, and what other obligations exist. Jumping to a technical control skips the essential assessment step.

  • ✓

    Conduct a gap analysis between the law’s requirements and the current security controls.

    Why this is correct

    A gap analysis is the logical first step because it identifies where the current program falls short of the legal requirements. Without understanding the gaps, the CISO cannot prioritize investments, assign resources or develop a credible compliance roadmap. The analysis provides the factual basis for all subsequent decisions, ensuring that remediation efforts target actual deficiencies rather than assumptions.

  • ✗

    Update the information security policy to reference the new law.

    Why it's wrong here

    Policy updates are important for governance, but revising policy before understanding the gaps can produce aspirational statements that the organization cannot yet meet. The CISO should first determine where controls fall short, then update policies to reflect achievable and required practices. Policy change without a gap analysis risks creating unenforceable requirements and misleading stakeholders about compliance readiness.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.