Courseiva

CISM Information Security Governance Practice Question

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

⚠ Common exam trap

CISM often tests the CMM level definitions by swapping adjacent levels — the trap is confusing Level 3 (Defined, standardized processes) with Level 4 (Quantitatively Managed, metrics) or Level 5 (Optimizing, continuous improvement).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standardized and documented security processes

CMM Level 3 is defined as 'Defined' — the organization has standardized, documented processes that are communicated and followed across the enterprise, rather than relying on individual heroics. At this level, process assets exist (policies, procedures, templates) and projects tailor them from a shared organizational set. This is the capability the organization must demonstrate to claim Level 3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Standardized and documented security processes

    Why this is correct

    CMM Level 3 requires defined, organisation-wide standardised processes, not the ad hoc or per-project approaches of Levels 1 and 2. Documented security processes applied consistently across the enterprise satisfy this definition, evidencing the institutionalisation the stem's maturity goal demands.

  • ✗

    Ad-hoc security processes

    Why it's wrong here

    Ad-hoc, undocumented processes characterise CMM Level 1, not Level 3. Level 3 demands defined processes that are documented, standardised and integrated across the organisation. Ad-hoc processes would be the expected state at Level 1, so this describes the opposite of the maturity goal.

  • ✗

    Quantitative measurement of process effectiveness

    Why it's wrong here

    Quantitative measurement of process effectiveness describes CMM Level 4, where processes are statistically controlled and measured. Level 3 requires defined, documented, standardised processes institutionalised across the organisation. Quantitative metrics would be the correct answer if the goal were Level 4 rather than Level 3.

  • ✗

    Continuous process optimization

    Why it's wrong here

    Continuous process optimisation is the defining capability of CMM Level 5, where processes are refined through ongoing improvement. Level 3 instead requires defined, documented and organisation-wide standardised processes. Continuous optimisation would be correct if the stated goal were Level 5.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.