Courseiva

CISM Information Security Programme Practice Question

A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?

⚠ Common exam trap

The trap here is assuming that technical testing or a single metric set is sufficient to judge programme effectiveness, when a broader, objective-driven review is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a formal programme review using defined metrics, control assessments, and stakeholder feedback.

Evaluating programme effectiveness requires a structured review that examines multiple dimensions: performance metrics, control effectiveness, risk posture, and stakeholder perspectives. This holistic approach reveals whether objectives are being met and highlights improvement areas. Technical testing or single-source feedback provides only partial insight and cannot support comprehensive programme evaluation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review the latest vulnerability scan reports and track remediation rates.

    Why it's wrong here

    Vulnerability scan reports and remediation rates are useful operational metrics, but they reflect only one dimension of the programme. They do not address governance, risk management, awareness, or strategic alignment. Relying on them alone would give an incomplete picture and could miss systemic issues, so this approach is insufficient for evaluating overall programme effectiveness.

  • ✗

    Run a full-scope penetration test against all external-facing applications.

    Why it's wrong here

    A penetration test evaluates the security of specific systems at a point in time and can reveal vulnerabilities, but it does not assess whether the overall programme is achieving its intended outcomes. It covers technical controls only and ignores governance, process, and people aspects. Therefore, it is too narrow to answer the CISO's broader question about programme effectiveness.

  • ✗

    Survey employees about their perceptions of the security team's responsiveness.

    Why it's wrong here

    Employee perception surveys can provide valuable insight into culture and service quality, but they are subjective and limited in scope. They do not measure control effectiveness, risk reduction, or alignment with business objectives. While useful as one input, a survey alone cannot determine whether the programme is achieving its intended outcomes or identify where improvements are most needed.

  • ✓

    Conduct a formal programme review using defined metrics, control assessments, and stakeholder feedback.

    Why this is correct

    A formal programme review that combines metrics, control assessments, and stakeholder feedback provides a comprehensive evaluation of whether the programme is meeting its objectives and where gaps exist. It goes beyond single-point technical testing by examining effectiveness, alignment, and maturity. This approach supports continuous improvement and gives the CISO evidence to justify changes or additional investment.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.