CISM Information Security Programme Practice Question
A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?
⚠ Common exam trap
The trap here is assuming that technical testing or a single metric set is sufficient to judge programme effectiveness, when a broader, objective-driven review is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a formal programme review using defined metrics, control assessments, and stakeholder feedback.
Evaluating programme effectiveness requires a structured review that examines multiple dimensions: performance metrics, control effectiveness, risk posture, and stakeholder perspectives. This holistic approach reveals whether objectives are being met and highlights improvement areas. Technical testing or single-source feedback provides only partial insight and cannot support comprehensive programme evaluation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the latest vulnerability scan reports and track remediation rates.
Why it's wrong here
Vulnerability scan reports and remediation rates are useful operational metrics, but they reflect only one dimension of the programme. They do not address governance, risk management, awareness, or strategic alignment. Relying on them alone would give an incomplete picture and could miss systemic issues, so this approach is insufficient for evaluating overall programme effectiveness.
- ✗
Run a full-scope penetration test against all external-facing applications.
Why it's wrong here
A penetration test evaluates the security of specific systems at a point in time and can reveal vulnerabilities, but it does not assess whether the overall programme is achieving its intended outcomes. It covers technical controls only and ignores governance, process, and people aspects. Therefore, it is too narrow to answer the CISO's broader question about programme effectiveness.
- ✗
Survey employees about their perceptions of the security team's responsiveness.
Why it's wrong here
Employee perception surveys can provide valuable insight into culture and service quality, but they are subjective and limited in scope. They do not measure control effectiveness, risk reduction, or alignment with business objectives. While useful as one input, a survey alone cannot determine whether the programme is achieving its intended outcomes or identify where improvements are most needed.
- ✓
Conduct a formal programme review using defined metrics, control assessments, and stakeholder feedback.
Why this is correct
A formal programme review that combines metrics, control assessments, and stakeholder feedback provides a comprehensive evaluation of whether the programme is meeting its objectives and where gaps exist. It goes beyond single-point technical testing by examining effectiveness, alignment, and maturity. This approach supports continuous improvement and gives the CISO evidence to justify changes or additional investment.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.