CISM Information Security Governance Practice Question
An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?
⚠ Common exam trap
CISM often tests the CMM level definitions by swapping adjacent levels — the trap is confusing Level 3 (Defined, standardized processes) with Level 4 (Quantitatively Managed, metrics) or Level 5 (Optimizing, continuous improvement).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standardized and documented security processes
CMM Level 3 is defined as 'Defined' — the organization has standardized, documented processes that are communicated and followed across the enterprise, rather than relying on individual heroics. At this level, process assets exist (policies, procedures, templates) and projects tailor them from a shared organizational set. This is the capability the organization must demonstrate to claim Level 3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Standardized and documented security processes
Why this is correct
CMM Level 3 requires defined, organisation-wide standardised processes, not the ad hoc or per-project approaches of Levels 1 and 2. Documented security processes applied consistently across the enterprise satisfy this definition, evidencing the institutionalisation the stem's maturity goal demands.
- ✗
Ad-hoc security processes
Why it's wrong here
Ad-hoc, undocumented processes characterise CMM Level 1, not Level 3. Level 3 demands defined processes that are documented, standardised and integrated across the organisation. Ad-hoc processes would be the expected state at Level 1, so this describes the opposite of the maturity goal.
- ✗
Quantitative measurement of process effectiveness
Why it's wrong here
Quantitative measurement of process effectiveness describes CMM Level 4, where processes are statistically controlled and measured. Level 3 requires defined, documented, standardised processes institutionalised across the organisation. Quantitative metrics would be the correct answer if the goal were Level 4 rather than Level 3.
- ✗
Continuous process optimization
Why it's wrong here
Continuous process optimisation is the defining capability of CMM Level 5, where processes are refined through ongoing improvement. Level 3 instead requires defined, documented and organisation-wide standardised processes. Continuous optimisation would be correct if the stated goal were Level 5.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.