Courseiva

CISM Information Security Programme Practice Question

A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?

⚠ Common exam trap

The trap here is relying on reactive measures like penetration testing or policy acknowledgments instead of proactively integrating security into the development process through training and automated gates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing a secure coding training program for developers and integrating security gates into the CI/CD pipeline.

The correct answer is implementing a secure coding training program for developers and integrating security gates into the CI/CD pipeline. This approach proactively builds security into the development process, reducing vulnerabilities at the source. Training equips developers to write secure code, and automated gates enforce security checks early and consistently. Together, they embed security into the SDLC effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outsourcing all security testing to a third-party vendor.

    Why it's wrong here

    Outsourcing testing can provide expertise but does not integrate security into the SDLC. It remains a separate activity, often performed late in the cycle. It also does not build internal capability or foster a security culture among developers. While it can supplement efforts, it is not the most effective way to achieve integration. A combination of internal training and process integration is superior.

  • ✓

    Implementing a secure coding training program for developers and integrating security gates into the CI/CD pipeline.

    Why this is correct

    Training developers on secure coding and embedding security gates into the CI/CD pipeline are proactive measures that integrate security throughout development. Training reduces the introduction of vulnerabilities, while automated gates catch issues early. This shifts security left, making it more efficient and cost-effective. It is the most effective way to embed security into the SDLC and reduce production vulnerabilities.

  • ✗

    Requiring developers to sign a security policy acknowledging their responsibilities.

    Why it's wrong here

    While policies and acknowledgments are important for accountability, they do not actively integrate security into the development process. They set expectations but do not provide the tools or knowledge to prevent vulnerabilities. This is a passive measure and insufficient on its own to achieve the desired integration. It should be part of a broader program but is not the most effective action.

  • ✗

    Conducting a penetration test after each major release.

    Why it's wrong here

    Penetration testing after release is a reactive measure that identifies vulnerabilities too late, when they are more costly to fix. It does not prevent vulnerabilities from being introduced during development. While valuable as a final check, it is not the most effective way to integrate security into the SDLC. A proactive approach is needed to build security in from the start.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.