CISM Information Security Programme Practice Question
An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?
⚠ Common exam trap
CISM often tests the difference between justifying a security investment with business-aligned evidence (cost-benefit, risk quantification) versus appealing to benchmarks or fear, so candidates who pick the peer-comparison answer mistake context for justification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Present a cost-benefit analysis showing breach avoidance value
A cost-benefit analysis that quantifies the value of avoided breaches translates the security gap into business terms (financial risk reduction, regulatory exposure, downtime cost), which is the language executives and the board use to approve budget. It directly addresses the CISO's need to justify the increase with evidence rather than comparison or emotion. This is the FIRST step because it builds the business case that supports any subsequent request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce other IT expenses to free up funds
Why it's wrong here
Reallocating existing IT spend addresses internal cost distribution, not the security programme's funding shortfall, and delivers no risk-based evidence to executives. It appeals because it appears fiscally responsible, yet reducing other IT expenses is a cost-optimisation tactic, not a justification mechanism for increasing the security budget.
- ✓
Present a cost-benefit analysis showing breach avoidance value
Why this is correct
A cost-benefit analysis translating security investment into avoided breach costs gives executives the financial evidence needed to justify closing the 8%-to-10-15% budget gap. Quantified breach avoidance directly addresses the benchmark shortfall identified in the stem.
- ✗
Request additional budget for emerging threats
Why it's wrong here
Requesting funds for emerging threats cites speculative future risks rather than the organisation's current exposure, giving decision-makers nothing measurable to approve. It appeals because emerging threats sound urgent and topical, but such requests belong in forward-looking roadmap planning, not the first step of evidence-based budget justification.
- ✗
Highlight the percentage gap compared to peers
Why it's wrong here
A peer percentage gap alone does not demonstrate organisational risk or unmet control needs, so it rarely persuades budget holders. It is tempting because benchmarking is quick and objective, and it would support a case once specific risk exposure and required controls have been quantified.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.