Courseiva

CISM Information Security Governance Practice Question

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

⚠ Common exam trap

CISM often tests the ordering of the policy lifecycle, and candidates frequently confuse pre-approval activities (consultation, gap analysis, legal review) with post-approval activities (training, communication, enforcement).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Training and communication

Once a security policy is formally approved, the organization must ensure everyone affected knows about it and understands how to comply — this is the training and communication phase. Awareness and training are what turn an approved document into actual behavior, and they are a required step in the policy lifecycle before enforcement and monitoring can be effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stakeholder consultation

    Why it's wrong here

    Consultation belongs before approval, since stakeholder input shapes the policy's content. Running it afterwards cannot alter an approved document and delays communication of the final policy to the workforce. It is tempting because consultation genuinely is essential during policy development, and in a scenario asking what precedes approval it would be the right answer.

  • ✗

    Gap analysis

    Why it's wrong here

    Gap analysis compares the approved policy against current controls and practices, so it necessarily follows approval; it identifies what must change to reach compliance. It is tempting because gap analysis is a legitimate post-approval activity, but it is not the immediate next step—communicating and implementing the policy comes first.

  • ✓

    Training and communication

    Why this is correct

    An approved policy is inert until staff know and follow it. Training and communication disseminates the approved requirements to affected personnel, ensuring awareness and enabling subsequent enforcement, monitoring and compliance activities that depend on people understanding their obligations.

  • ✗

    Legal review

    Why it's wrong here

    Legal review must precede approval so counsel can flag regulatory conflicts before the policy becomes binding; afterwards it can only trigger amendment. It is tempting because legal review is genuinely required for policies touching privacy, employment or cross-border data, and would be correct when the question asks which step validates a draft before sign-off.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.