CISM Information Security Governance Practice Question
An organization is updating its information security policy framework. The CISO wants to ensure that the policies are effectively communicated and understood by all employees. Which of the following is the MOST effective method to achieve this?
⚠ Common exam trap
The trap here is equating acknowledgment or passive communication with effective understanding, when active learning and assessment are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct regular, role-based training sessions that include practical examples and quizzes to reinforce policy concepts.
Role-based training with practical examples and quizzes is the most effective method because it actively engages employees, tailors content to their responsibilities, and measures comprehension. It ensures that policies are not just distributed but understood and applied, which is essential for effective security governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish the policies on the corporate intranet and send an email announcement to all staff.
Why it's wrong here
Publishing policies and sending an email is a passive communication method. It relies on employees to seek out and read the policies, which many may not do. There is no assurance that employees will understand or remember the content. This approach lacks interactivity and measurement, making it less effective for ensuring comprehension and compliance.
- ✗
Include a summary of the policies in the employee handbook provided at hire.
Why it's wrong here
Including policies in the employee handbook is useful for initial awareness but is not sufficient for ongoing communication or understanding. Policies change, and employees may not refer back to the handbook regularly. A summary may omit critical details. This method does not provide the interactive reinforcement needed to ensure employees understand and apply the policies correctly.
- ✓
Conduct regular, role-based training sessions that include practical examples and quizzes to reinforce policy concepts.
Why this is correct
Role-based training with practical examples and quizzes actively engages employees and verifies understanding. It tailors the content to specific job functions, making policies relevant and easier to apply. Quizzes provide measurable feedback on comprehension. This method goes beyond mere dissemination and ensures that employees not only receive but also understand and can apply the policies in their daily work.
- ✗
Require all employees to sign an acknowledgment form after reading the policies.
Why it's wrong here
Signing an acknowledgment may provide legal evidence of receipt but does not ensure understanding or effective communication. Employees might sign without fully comprehending the policies. This method is more about compliance documentation than actual comprehension. It does not actively engage employees or verify that they understand how the policies apply to their roles.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.