Courseiva

CISM Information Security Governance Practice Question

An organization has recently experienced a data breach that resulted in reputational damage and regulatory fines. The board has asked the CISO to improve the information security governance framework to prevent future incidents. Which of the following should the CISO do FIRST?

⚠ Common exam trap

The trap here is jumping to solutions like policy updates or new technology before understanding the root cause of the breach through a post-incident review.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a post-incident review to identify root causes and lessons learned.

The first step after a breach is to conduct a post-incident review to identify root causes and lessons learned. This evidence-based approach ensures that subsequent improvements to the governance framework are targeted and effective. It helps the CISO understand whether the breach resulted from policy failures, control gaps, or other issues, enabling informed decisions about changes to governance, policies, and controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a new security information and event management (SIEM) system.

    Why it's wrong here

    Purchasing and implementing a SIEM is a technical solution that may or may not address the root cause. Without a thorough review, the organization risks investing in technology that does not solve the underlying governance or control weaknesses. The CISO should first understand why the breach occurred and then determine if a SIEM is part of the solution. Technology alone is not a governance fix.

  • ✗

    Increase the security budget to hire more security staff.

    Why it's wrong here

    Increasing budget and staff may be necessary, but it is not the first step. Without understanding the specific gaps that led to the breach, additional resources may be misallocated. The CISO needs to assess the situation and identify where improvements are needed. A post-incident review provides the evidence to justify resource requests and ensure they are targeted at the right areas.

  • ✗

    Update the security policy to include stricter penalties for non-compliance.

    Why it's wrong here

    Updating policies without understanding the root cause of the breach is premature. The breach may have occurred due to technical failures, process gaps, or cultural issues, not necessarily policy non-compliance. Stricter penalties may not address the actual problem and could damage morale. A post-incident review should precede policy changes to ensure they are targeted and effective.

  • ✓

    Conduct a post-incident review to identify root causes and lessons learned.

    Why this is correct

    Conducting a post-incident review is the first step to understand what went wrong and why. It identifies root causes, gaps in controls, and governance failures. This information is essential for making informed improvements to the governance framework. Without this analysis, any changes may be based on assumptions rather than evidence, and similar incidents could recur.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.