Courseiva

CISM Information Security Programme Practice Question

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

⚠ Common exam trap

The trap is that candidates choose compliance or benchmarking because they sound authoritative, but CISM favors business-aligned, value-based justifications like breach avoidance over comparative or minimum-requirement arguments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Breach avoidance value, estimating the cost of incidents that were prevented.

Breach avoidance value quantifies the cost of incidents that were prevented, directly linking security spending to avoided financial loss and risk reduction. This is the strongest justification because it speaks the board's language — return on security investment — and demonstrates measurable value rather than relative positioning or compliance minimums.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Benchmarking against industry peers showing that the proposed budget is below average.

    Why it's wrong here

    Peer benchmarking compares spend against others, not against this organisation's own risk exposure, so it cannot demonstrate that the increase reduces identified risk. It is tempting because benchmarking is a recognised governance tool, and it would be valid when assessing whether current spending is proportionate to sector norms.

  • ✓

    Breach avoidance value, estimating the cost of incidents that were prevented.

    Why this is correct

    Breach avoidance value quantifies incidents prevented, directly translating security spend into avoided financial loss. This satisfies the board's demand for justification by expressing the increase in monetary terms the board already uses for investment decisions, rather than technical or compliance language.

  • ✗

    Operational efficiency gains from automation of security processes.

    Why it's wrong here

    Automation efficiency reduces existing operating cost; it does not justify additional funding, since savings argue for a smaller budget. It is tempting because efficiency is a legitimate security programme goal, and it would be the correct justification when the board asks how to deliver current capability within the existing allocation.

  • ✗

    Compliance with all regulatory requirements to avoid fines.

    Why it's wrong here

    Regulatory compliance represents a mandatory baseline already funded within the mature programme; it evidences no new risk reduction from the increase. It is tempting because fines are tangible, and compliance would be the strongest justification where the organisation currently fails an applicable regulatory obligation.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.