CISM Information Security Programme Practice Question
An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?
⚠ Common exam trap
The trap is that candidates choose compliance or benchmarking because they sound authoritative, but CISM favors business-aligned, value-based justifications like breach avoidance over comparative or minimum-requirement arguments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Breach avoidance value, estimating the cost of incidents that were prevented.
Breach avoidance value quantifies the cost of incidents that were prevented, directly linking security spending to avoided financial loss and risk reduction. This is the strongest justification because it speaks the board's language — return on security investment — and demonstrates measurable value rather than relative positioning or compliance minimums.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Benchmarking against industry peers showing that the proposed budget is below average.
Why it's wrong here
Peer benchmarking compares spend against others, not against this organisation's own risk exposure, so it cannot demonstrate that the increase reduces identified risk. It is tempting because benchmarking is a recognised governance tool, and it would be valid when assessing whether current spending is proportionate to sector norms.
- ✓
Breach avoidance value, estimating the cost of incidents that were prevented.
Why this is correct
Breach avoidance value quantifies incidents prevented, directly translating security spend into avoided financial loss. This satisfies the board's demand for justification by expressing the increase in monetary terms the board already uses for investment decisions, rather than technical or compliance language.
- ✗
Operational efficiency gains from automation of security processes.
Why it's wrong here
Automation efficiency reduces existing operating cost; it does not justify additional funding, since savings argue for a smaller budget. It is tempting because efficiency is a legitimate security programme goal, and it would be the correct justification when the board asks how to deliver current capability within the existing allocation.
- ✗
Compliance with all regulatory requirements to avoid fines.
Why it's wrong here
Regulatory compliance represents a mandatory baseline already funded within the mature programme; it evidences no new risk reduction from the increase. It is tempting because fines are tangible, and compliance would be the strongest justification where the organisation currently fails an applicable regulatory obligation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.