Courseiva

CISM Information Security Program Practice Question

An organization's information security program has a documented risk management process. During a review, the CISO finds that risk assessments are performed annually but do not account for changes in the threat landscape or business environment. Which of the following is the BEST recommendation to improve the program?

⚠ Common exam trap

The trap here is assuming that increasing assessment frequency or adopting a new framework will solve the problem, but without integration with change management, assessments remain disconnected from real-time changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a continuous risk assessment process integrated with change management.

Implementing a continuous risk assessment process integrated with change management is the best recommendation because it ensures that risk assessments are performed whenever significant changes occur, not just annually. This dynamic approach keeps the risk register current and enables the organization to respond to emerging threats and business changes effectively, improving overall risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outsource risk assessments to a third-party specialist.

    Why it's wrong here

    Outsourcing may bring expertise but does not inherently make the process continuous or aligned with internal changes. The organization still needs to integrate risk assessment with its own change management. Outsourcing could also reduce internal ownership and responsiveness, making it less effective for dynamic risk management.

  • ✗

    Increase the frequency of risk assessments to quarterly.

    Why it's wrong here

    Increasing frequency alone does not ensure that assessments account for changes. If the methodology remains static, quarterly assessments may still miss emerging threats. The key is to adopt a continuous or event-driven approach that triggers reassessment when significant changes occur, rather than just increasing the interval.

  • ✗

    Adopt a risk assessment framework such as OCTAVE or FAIR.

    Why it's wrong here

    Adopting a framework can improve methodology but does not address the need for continuous updates. Without integration into change management, assessments may still be periodic and miss real-time changes. The framework alone does not solve the timeliness issue; the process must be triggered by relevant changes.

  • ✓

    Implement a continuous risk assessment process integrated with change management.

    Why this is correct

    Integrating continuous risk assessment with change management ensures that risks are evaluated whenever there are changes in the business environment, technology, or threat landscape. This dynamic approach allows the organization to adapt quickly to new risks, improving the effectiveness of the risk management process and aligning with business objectives.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.