CISM Information Security Program Practice Question
An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?
⚠ Common exam trap
The trap here is focusing on operational activities like training or risk assessments before securing executive mandate and governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A formal security charter approved by executive management.
A formal security charter approved by executive management is the most important first step because it establishes the program's authority, scope, and resources. It ensures that security is aligned with business objectives and provides the CISO with the mandate to implement and enforce the program. Without this foundation, other activities may lack support and effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An incident response plan.
Why it's wrong here
An incident response plan is essential for managing security incidents, but it is a component of the overall program. It should be developed after the program's governance structure is in place. Without authority and resources, the plan may not be effectively implemented or maintained. The charter establishes the program's foundation.
- ✗
A security awareness training program.
Why it's wrong here
Security awareness training is an important component, but it comes after governance and authority are established. Without a mandate and resources, training efforts may lack support and funding. It is a tactical activity that should follow the strategic establishment of the program's foundation, including charter and executive sponsorship.
- ✗
A comprehensive risk assessment.
Why it's wrong here
A risk assessment is critical for identifying and prioritizing risks, but it requires a foundation of authority and resources to act upon its findings. Without a charter, the program may not have the mandate to conduct assessments or implement treatments. Thus, the charter should come first to enable the risk assessment process.
- ✓
A formal security charter approved by executive management.
Why this is correct
A formal security charter approved by executive management provides the program with authority, scope, and resources. It defines the CISO's mandate, establishes accountability, and ensures alignment with business objectives. Without a charter, the program may lack the necessary support and legitimacy to enforce policies and implement controls effectively.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.