easyMultiple Choice
CISM Practice Question: An information security manager is developing a…
An information security manager is developing a security strategy for a financial institution. Which of the following should be the PRIMARY driver for selecting security controls?
⚠ Common exam trap
The trap here is that candidates often pick 'past security incidents' (Option B) because it feels intuitive, but CISM emphasizes a proactive, risk-based governance approach where business requirements and compliance drive control selection, not historical events or budget constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business requirements derived from risk assessment and compliance obligations.
Business requirements derived from risk assessment and compliance obligations are the primary driver because they directly align security controls with the institution's specific risk appetite, regulatory mandates (e.g., PCI DSS, SOX, GDPR), and operational needs. This ensures controls are cost-effective and prioritized based on actual exposure rather than reactive or budget-driven decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The latest cybersecurity threats reported in the industry.
Why it's wrong here
Threat headlines are not a control-selection criterion; controls must map to the institution's own risk assessment and regulatory obligations. Industry reporting is tempting because it feels current, and it is genuinely useful for threat intelligence and awareness briefings, but it cannot establish which controls the financial institution actually requires.
- ✗
Past security incidents that caused significant financial loss.
Why it's wrong here
Past incidents are historical and reactive; control selection should follow from the institution's risk assessment and regulatory obligations, not prior losses alone. It is tempting because realised losses justify spending, but that suits post-incident reviews or budget justification, not the primary strategic driver.
- ✓
Business requirements derived from risk assessment and compliance obligations.
Why this is correct
Controls must map to business requirements, which risk assessment and compliance obligations define. This ties spending to the institution's actual risk exposure and regulatory duties, ensuring security supports business objectives rather than technology preferences or vendor defaults.
- ✗
The security budget allocated for the fiscal year.
Why it's wrong here
Budget constrains what can be implemented but cannot determine which controls the institution's risk profile and regulatory requirements demand. It is tempting because affordability shapes roadmaps, but that suits sequencing approved controls, not selecting them; risk appetite and compliance obligations drive selection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.