CISM Information Security Governance Practice Question
An organization has recently experienced a data breach that resulted in the loss of customer personally identifiable information (PII). The board of directors is concerned about the effectiveness of the information security governance program. Which of the following should the CISO recommend as the MOST important action to improve governance?
⚠ Common exam trap
The trap here is assuming that a breach always requires more technology, training, or personnel action, when the first step should be to understand the root cause through a structured review.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a post-incident review to identify root causes and update security policies and controls accordingly.
Conducting a post-incident review is the most important action because it systematically identifies what went wrong and how to improve policies, controls, and governance. It provides the board with assurance that the organization is learning from the incident and taking concrete steps to prevent recurrence, which is a key aspect of effective governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a post-incident review to identify root causes and update security policies and controls accordingly.
Why this is correct
A post-incident review is critical for learning from the breach and improving governance. It identifies root causes, evaluates the effectiveness of existing controls and policies, and recommends improvements. This action directly addresses the board's concern by demonstrating a commitment to continuous improvement and strengthening the governance framework based on real-world events. It also helps prevent future incidents.
- ✗
Implement a new security awareness training program for all employees.
Why it's wrong here
Security awareness training is valuable, but without understanding why the breach occurred, it may not be the most important action. The breach could have been caused by a technical vulnerability, a process gap, or a policy failure. Training alone may not address these issues. A post-incident review is needed first to determine the appropriate corrective actions, which may include training.
- ✗
Terminate the employees responsible for the breach to demonstrate accountability.
Why it's wrong here
Terminating employees may be a knee-jerk reaction and does not improve governance. It could create a culture of fear and discourage reporting. The focus should be on systemic improvements, not blame. Governance is about structures and processes, not individual punishment. This action does not address the root causes or prevent future breaches.
- ✗
Increase the security budget to purchase additional security technologies.
Why it's wrong here
While additional technologies may help, simply increasing the budget without understanding the root cause of the breach may not improve governance. The breach might have been due to process failures, lack of training, or misalignment with business strategy. Throwing money at technology without a strategic review is not the most effective governance improvement. It does not address the underlying issues.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.