Courseiva
easyMultiple Choice

CISM Practice Question: Has recently experienced a data breach due to an…

An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?

⚠ Common exam trap

It's easy for candidates to confuse tactical security controls (like MFA or EDR) with governance improvements, failing to recognize that the board's request specifically targets the need for a structured program with defined accountability, not just additional technology layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Developing a formalized insider threat program with clear roles and responsibilities.

A formalized insider threat program with clear roles and responsibilities is the first governance improvement because it establishes a structured framework for detecting, preventing, and responding to insider threats. Unlike tactical controls, this program defines ownership, escalation paths, and policy integration, directly addressing the board's request for governance improvements rather than just technical fixes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Developing a formalized insider threat program with clear roles and responsibilities.

    Why this is correct

    A formalised insider threat programme establishes accountable ownership, defined roles and repeatable detection, response and monitoring processes. This directly addresses the governance gap exposed by the breach, giving the board assurance that insider risk is now managed rather than ad hoc.

  • ✗

    Conducting annual security awareness training for all employees.

    Why it's wrong here

    Annual awareness training is a control activity, not a governance improvement; the board requested changes to oversight, policy and accountability structures. Training is the correct first recommendation when the root cause is demonstrated staff ignorance of policy, rather than a governance framework that failed to constrain insider activity.

  • ✗

    Implementing two-factor authentication for all critical systems.

    Why it's wrong here

    Two-factor authentication is a technical access control; it does not constitute the governance improvement the board requested after an insider breach. It would be the correct first recommendation when the identified weakness is credential compromise or weak authentication on critical systems, rather than absent governance oversight and accountability.

  • ✗

    Deploying endpoint detection and response (EDR) software on all systems.

    Why it's wrong here

    EDR detects and responds to malicious endpoint behaviour, but the board asked for governance improvements, so a technical control addresses symptoms rather than oversight, policy and accountability. EDR is the right recommendation when the gap is detection capability against malware or lateral movement, not when governance structures need strengthening after an insider incident.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.