CISM Information Security Programme Practice Question
An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?
⚠ Common exam trap
The trap here is assuming that maximum implementation of every catalogue control equals the strongest programme, when frameworks are meant to be tailored by risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopt a comprehensive control catalogue as the baseline, then tailor control selection and implementation using the organisation's risk assessment results.
Control frameworks are designed to be adopted as a baseline and then tailored through risk assessment, which gives both completeness and proportionality. Implementing everything at maximum strength wastes resources, letting each unit choose its own framework destroys comparability, and a purely bespoke set risks blind spots that established catalogues are designed to prevent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adopt a comprehensive control catalogue as the baseline, then tailor control selection and implementation using the organisation's risk assessment results.
Why this is correct
This combines the breadth of a recognised catalogue with risk-based tailoring, which is how control frameworks are intended to be used. The catalogue provides completeness and a common reference, while risk assessment determines which controls are relevant, how strictly they are applied and where compensating measures are acceptable, keeping effort proportionate to actual exposure.
- ✗
Build a bespoke control set from scratch based on internal incident history, avoiding external frameworks that may not reflect the organisation's environment.
Why it's wrong here
A bespoke set built only on internal history is likely to miss control areas the organisation has not yet experienced, such as emerging threat vectors or regulatory expectations. External frameworks encode broad industry experience, so discarding them removes a valuable completeness check and increases the chance of significant blind spots.
- ✗
Implement every control in the chosen catalogue to the highest specified level so that no gap can ever be identified by an auditor.
Why it's wrong here
Blanket implementation at maximum strength consumes budget and effort on controls that may be irrelevant to the organisation's risk profile, leaving less capacity for the risks that matter most. Auditors assess whether controls are appropriate and effective for the risks, not whether every possible control exists, so this approach is both wasteful and strategically misaligned.
- ✗
Allow each business unit to select controls from any framework it prefers, provided the unit documents its choices in its own risk register.
Why it's wrong here
Permitting different frameworks per unit destroys comparability and prevents the CISO from aggregating risk or demonstrating consistent control to regulators and customers. Documentation in local registers does not fix the underlying problem of incompatible taxonomies, duplicated tooling and an inability to state the organisation's overall control posture.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.