Courseiva

CISM Information Security Governance Practice Question

An organization's information security strategy is being updated to align with the business goal of expanding into new markets. The CISO must ensure that the strategy addresses the varying legal and regulatory requirements of these markets. Which of the following should be the PRIMARY consideration when updating the strategy?

⚠ Common exam trap

The trap here is prioritizing cost or technical feasibility over the fundamental business risk of non-compliance, which could prevent market entry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential impact of regulatory non-compliance on the organization's reputation and ability to operate.

When updating the security strategy to support business expansion, the primary consideration is the impact of regulatory non-compliance, as it directly affects the organization's ability to operate in new markets and its reputation. This ensures that the strategy is aligned with business objectives and prioritizes risk management. Other factors like cost, resources, and framework extensibility are important but secondary to understanding and mitigating compliance risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cost of implementing additional security controls required by new regulations.

    Why it's wrong here

    While cost is an important factor, it is not the primary consideration. The strategy must first ensure that the organization can legally operate in the new markets by meeting regulatory requirements. Cost considerations come into play when selecting controls, but the primary focus should be on achieving compliance and managing risk to enable business expansion.

  • ✗

    The existing security control framework's ability to be extended to cover new requirements.

    Why it's wrong here

    Extending the existing framework is a practical approach, but it is not the primary consideration. The strategy must be driven by the business need to comply with new regulations and manage associated risks. The framework's extensibility is a technical detail that should be evaluated after the strategic requirements are clear.

  • ✗

    The availability of security personnel with expertise in the new markets' regulations.

    Why it's wrong here

    While having skilled personnel is important for implementation, it is not the primary consideration when updating the strategy. The strategy should first define what needs to be achieved based on regulatory requirements and risk. Resource availability is a tactical concern that can be addressed through hiring, training, or partnerships once the strategic direction is set.

  • ✓

    The potential impact of regulatory non-compliance on the organization's reputation and ability to operate.

    Why this is correct

    The primary consideration should be the impact of non-compliance, as it can result in fines, legal penalties, and reputational damage that could derail the expansion. By understanding the regulatory landscape and the consequences of non-compliance, the CISO can prioritize controls and ensure the strategy supports business objectives while managing risk.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.