CISM Information Security Governance Practice Question
An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
⚠ Common exam trap
CISM often tests the ordering of the policy lifecycle, and candidates frequently confuse pre-approval activities (consultation, gap analysis, legal review) with post-approval activities (training, communication, enforcement).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Training and communication
Once a security policy is formally approved, the organization must ensure everyone affected knows about it and understands how to comply — this is the training and communication phase. Awareness and training are what turn an approved document into actual behavior, and they are a required step in the policy lifecycle before enforcement and monitoring can be effective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stakeholder consultation
Why it's wrong here
Consultation belongs before approval, since stakeholder input shapes the policy's content. Running it afterwards cannot alter an approved document and delays communication of the final policy to the workforce. It is tempting because consultation genuinely is essential during policy development, and in a scenario asking what precedes approval it would be the right answer.
- ✗
Gap analysis
Why it's wrong here
Gap analysis compares the approved policy against current controls and practices, so it necessarily follows approval; it identifies what must change to reach compliance. It is tempting because gap analysis is a legitimate post-approval activity, but it is not the immediate next step—communicating and implementing the policy comes first.
- ✓
Training and communication
Why this is correct
An approved policy is inert until staff know and follow it. Training and communication disseminates the approved requirements to affected personnel, ensuring awareness and enabling subsequent enforcement, monitoring and compliance activities that depend on people understanding their obligations.
- ✗
Legal review
Why it's wrong here
Legal review must precede approval so counsel can flag regulatory conflicts before the policy becomes binding; afterwards it can only trigger amendment. It is tempting because legal review is genuinely required for policies touching privacy, employment or cross-border data, and would be correct when the question asks which step validates a draft before sign-off.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.