easyMultiple Choice
CISM Practice Question: Has recently experienced a data breach due to an…
An organization has recently experienced a data breach due to an insider threat. The board has requested an update on governance improvements. Which of the following should the information security manager recommend first?
⚠ Common exam trap
It's easy for candidates to confuse tactical security controls (like MFA or EDR) with governance improvements, failing to recognize that the board's request specifically targets the need for a structured program with defined accountability, not just additional technology layers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Developing a formalized insider threat program with clear roles and responsibilities.
A formalized insider threat program with clear roles and responsibilities is the first governance improvement because it establishes a structured framework for detecting, preventing, and responding to insider threats. Unlike tactical controls, this program defines ownership, escalation paths, and policy integration, directly addressing the board's request for governance improvements rather than just technical fixes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Developing a formalized insider threat program with clear roles and responsibilities.
Why this is correct
A formalised insider threat programme establishes accountable ownership, defined roles and repeatable detection, response and monitoring processes. This directly addresses the governance gap exposed by the breach, giving the board assurance that insider risk is now managed rather than ad hoc.
- ✗
Conducting annual security awareness training for all employees.
Why it's wrong here
Annual awareness training is a control activity, not a governance improvement; the board requested changes to oversight, policy and accountability structures. Training is the correct first recommendation when the root cause is demonstrated staff ignorance of policy, rather than a governance framework that failed to constrain insider activity.
- ✗
Implementing two-factor authentication for all critical systems.
Why it's wrong here
Two-factor authentication is a technical access control; it does not constitute the governance improvement the board requested after an insider breach. It would be the correct first recommendation when the identified weakness is credential compromise or weak authentication on critical systems, rather than absent governance oversight and accountability.
- ✗
Deploying endpoint detection and response (EDR) software on all systems.
Why it's wrong here
EDR detects and responds to malicious endpoint behaviour, but the board asked for governance improvements, so a technical control addresses symptoms rather than oversight, policy and accountability. EDR is the right recommendation when the gap is detection capability against malware or lateral movement, not when governance structures need strengthening after an insider incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.