Courseiva

CISM · domain

Information Security Program

This domain covers building, governing, and continuously improving an information security program. CISM questions here test how you align security with business objectives, assign ownership, apply policies and standards, and move an organization from reactive to proactive. Expect scenario-based questions about governance structures, data classification, metrics, and program maturity rather than hands-on tool configuration.

139 questions37 easy55 medium47 hard

Focused practice

Practice Information Security Program questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Security Program

You must be able to select governance, policy, and program-management actions that align security with business goals and enforce standards. The single most important thing is to identify who owns the risk and the control, then choose the action that improves accountability and proactive risk management.

Aligning security strategy, policies, and standards with business objectives and risk appetite

Assigning security roles, responsibilities, and accountability across business units and the CISO

Establishing data classification, ownership, and handling standards, and enforcing compliance

Using metrics, audits, and maturity models to move from reactive to proactive security

Why learners struggle

Why Information Security Program questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Information Security Program exam traps

  • ▸Choosing a technical control or tool when the real issue is governance, policy enforcement, or unclear ownership.
  • ▸Treating policy noncompliance as a training problem instead of an accountability and enforcement gap.
  • ▸Selecting a reactive activity, such as incident response, when the question asks for a proactive program initiative.

Question index

All Information Security Program questions (139)

Click any question to see the full explanation, or start a practice session above.

1

You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?

Easy
2

A multinational corporation is implementing a new information security program. The program manager needs to ensure that security requirements are integrated into the procurement process for third-party services. Which of the following is the most effective approach?

Medium
3

You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?

Medium
4

A global e-commerce company is designing its information security program. The CISO wants to implement a defense-in-depth strategy for the web application layer. Which combination of controls best achieves this objective?

Hard
5

A CISO is building a new information security program for a multinational financial services firm. The board has approved a budget but wants assurance that security investments are aligned with business objectives. Which of the following should the CISO do FIRST to establish this alignment?

Medium
6

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

Medium
7

Which of the following are key components of a mature information security program? (Select 2)

Hard
8

An organization wants to ensure that its security program aligns with business objectives. Which activity is most important?

Easy
9

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

Easy
10

Which of the following best describes the primary purpose of an Information Security Program?

Medium
11

Which THREE characteristics indicate a higher maturity level in a security program maturity model?

Hard
12

Which THREE of the following are common challenges in implementing an information security program across a large enterprise?

Hard
13

A CISO at a financial services firm is aligning the information security program with the business strategy. The organization is pursuing a merger that will significantly expand its customer base and require integration of disparate IT environments. The board wants assurance that security risks are managed during the merger. Which of the following should the CISO do FIRST?

Medium
14

A security manager is developing a new information security program for a mid-sized company. Which of the following should be the FIRST step?

Easy
15

A CISO is defining the scope of the information security program. The organization has multiple locations and uses cloud services extensively. Which factor is MOST important to consider when defining the program's scope?

Easy
16

A CISO is developing a set of key performance indicators (KPIs) for the information security program to report to the board. Which of the following are appropriate KPIs for measuring the effectiveness of the security program? (Choose two.)

Medium
17

Which of the following is the PRIMARY responsibility of a steering committee in an information security program?

Easy
18

An organization has multiple business units with different risk tolerances. How should the security program address this?

Hard
19

An organization's information security program has a documented risk management process. During a review, the CISO finds that risk assessments are performed annually but do not account for changes in the threat landscape or business environment. Which of the following is the BEST recommendation to improve the program?

Hard
20

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget, and they report to their respective business unit leaders. The CISO has limited authority over these teams. A recent incident revealed inconsistent security controls across business units, and the board is concerned about the overall risk posture. Which of the following should the CISO recommend to improve the program's effectiveness?

Medium
21

During a security assessment, an organization discovers that its patch management process is not consistently applied across all systems. Which of the following controls would best address this deficiency as part of the information security program?

Medium
22

Which TWO of the following are primary objectives of a security awareness program?

Easy
23

An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?

Medium
24

A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?

Hard
25

A CISO is reviewing the organization's information security program and wants to improve its maturity. Which of the following are characteristics of a mature information security program? (Choose two.)

Medium
26

An auditor reviews the BYOD policy and notes that mobile device management (MDM) logs show several devices without encryption. The policy has been in effect for 6 months. Which of the following is the most likely reason for this non-compliance?

Medium
27

A company has a small security team and limited budget. Which initial investment provides the MOST value for building an effective security program?

Easy
28

An information security manager is designing a program for a healthcare organization. Which of the following should be the FIRST step in establishing the program?

Medium
29

A multinational corporation is designing an information security program to align with diverse business units and regulatory requirements across different regions. The CISO is prioritizing key components that ensure the program is both comprehensive and adaptable. Which TWO components are most critical for achieving this alignment?

Medium
30

An organization's information security program includes a formal exception process. When reviewing an exception request to bypass a critical control, what is the MOST important factor for the information security manager to consider?

Hard
31

An information security manager is evaluating the maturity of the organization's security program. Which of the following indicators suggest a high level of maturity? (Select TWO.)

Hard
32

An organization is establishing an information security program. The CISO wants to ensure that the program has the necessary authority and resources. Which of the following is the MOST important to establish first?

Easy
33

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

Medium
34

A startup company is developing its first information security program. The CISO has been asked to present a business case to the executive team for funding the program. The CISO wants to demonstrate how the program will support business objectives and manage risk. Which of the following should the CISO include in the business case to BEST achieve this?

Easy
35

Based on the risk register entry, what is the primary gap in the current controls?

Easy
36

A multinational corporation has a decentralized information security program. Each business unit manages its own security budget and controls, leading to inconsistent practices and duplicated efforts. The CISO wants to improve program efficiency and effectiveness while respecting business unit autonomy. Which of the following is the BEST approach?

Medium
37

A CISO has implemented a security program based on ISO/IEC 27001. During a management review, the CIO asks how the program contributes to business value. Which of the following metrics would BEST demonstrate the program's contribution to business value?

Hard
38

An information security program is being developed for a multinational organization. Which of the following is the PRIMARY driver for aligning the security program with business objectives?

Medium
39

An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?

Hard
40

You are the information security program manager at a global financial services firm. The firm has a mature security program, but the CISO is concerned that the program is not keeping pace with emerging threats such as supply chain attacks and advanced persistent threats (APTs). Additionally, the program currently focuses heavily on compliance with regulations (e.g., PCI DSS, GDPR) rather than proactive risk management. The board wants to see a more strategic approach to information security. However, the compliance team is large and influential, and they resist changes that might reduce their role. You have been asked to propose a new program model that addresses these concerns while maintaining regulatory compliance. What should you do?

Medium
41

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

Easy
42

A healthcare organization has a security program that relies on a risk assessment conducted three years ago. Since then, the organization has adopted cloud services and telehealth, and new privacy regulations have been enacted. The CISO is concerned that the current security controls may not adequately address the new risks. Which of the following should the CISO do FIRST to ensure the program remains effective?

Hard
43

A multinational corporation with a decentralized information security program has recently experienced a data breach involving customer PII. The breach originated from a regional office that had not implemented the global security baseline due to local IT staff claiming 'unique operational requirements.' The CISO has tasked the security manager with revising the program to prevent recurrence. The organization has 12 regional offices, each with its own IT leadership, and a central security team. The budget is tight, and there is resistance to centralized control. Which of the following is the BEST course of action for the security manager?

Hard
44

A security program includes multiple metrics. Which metric best indicates the program's effectiveness in reducing overall risk?

Hard
45

Which document should be reviewed and updated at least annually?

Easy
46

Which THREE of the following are key performance indicators (KPIs) for an information security program?

Medium
47

Which TWO of the following are essential components of a security program governance structure?

Medium
48

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

Hard
49

A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?

Hard
50

Arrange the steps for implementing a new firewall rule in an enterprise environment.

Medium
51

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Hard
52

A small business is developing its first information security program. Which approach is most effective?

Easy
53

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget. The CISO wants to improve consistency and reduce duplication of efforts. Which of the following is the MOST effective approach?

Hard
54

Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?

Hard
55

Which of the following are key components of an information security program's strategic plan? (Select two.)

Medium
56

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to the business and driving continuous improvement. Which of the following are the MOST appropriate key performance indicators (KPIs) for the information security program? (Choose two.)

Hard
57

An organization's security program includes metrics to measure performance. Which metric BEST indicates the effectiveness of the vulnerability management process?

Medium
58

A global organization has a policy that requires all employees to complete security awareness training within 30 days of hire and annually thereafter. During an audit, it was found that only 60% of employees completed the annual training. The CISO needs to address this non-compliance. Which of the following should be the FIRST step?

Medium
59

During a security audit, several deviations from policy are found. What should the security manager do first?

Medium
60

Which of the following is the primary purpose of an Information Security Program?

Easy
61

Which TWO of the following are essential components of an information security program charter?

Easy
62

A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?

Hard
63

A CISO is establishing a security governance framework for a decentralized organization where each business unit operates independently. The CISO wants to ensure that security policies are consistently applied while respecting business unit autonomy. Which two actions are MOST appropriate to achieve this? (Choose two.)

Hard
64

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

Hard
65

Which TWO of the following are key performance indicators (KPIs) for measuring the effectiveness of an information security program?

Easy
66

An organization has a mature security program but is experiencing an increase in successful social engineering attacks. The incident response team has confirmed that the attacks are bypassing current controls. What should the program manager do first?

Medium
67

Which document should be created FIRST when establishing an information security program?

Easy
68

Which of the following are key components of an effective information security program? (Select TWO.)

Medium
69

A company's security program includes a set of controls based on a risk assessment. During an audit, several controls are found to be ineffective. What should the security manager do first?

Medium
70

An information security program must include elements to ensure continuous improvement. Which TWO of the following are MOST essential for continuous improvement?

Medium
71

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

Medium
72

Which of the following are key components of an information security program? (Select TWO)

Easy
73

An organization's information security program has been operational for two years. The security manager is asked to propose changes to improve effectiveness. Which approach should the manager take first?

Hard
74

Arrange the steps for performing a vulnerability scan on a network segment.

Medium
75

A healthcare organization's information security program has a risk register with several high-risk items. The CISO is allocating budget for risk treatment. Which of the following is the MOST important factor when deciding whether to mitigate, transfer, or accept a risk?

Hard
76

An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?

Easy
77

An organization wants to ensure its information security program is aligned with business objectives. Which of the following is the BEST approach?

Easy
78

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

Hard
79

An organization has a security program that is aligned with ISO 27001. During an internal audit, it is discovered that several controls are not being applied consistently across all departments. The MOST effective corrective action is to:

Hard
80

An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?

Medium
81

Which of the following is the most important factor for ensuring the long-term success of an information security program?

Easy
82

A security program lacks executive support. What is the best strategy to gain support?

Hard
83

An organization is updating its information security program to align with business objectives. Which of the following is the PRIMARY benefit of integrating security risk management into the strategic planning process?

Easy
84

After a data breach, the CISO reviews the security program. The breach exploited a known vulnerability in a legacy system that was deemed 'acceptable risk' two years ago. What should the CISO do to improve the program?

Hard
85

A CISO is developing a business case for a new security initiative. The organization's executives are focused on cost reduction and operational efficiency. Which of the following approaches is BEST to gain executive support?

Medium
86

A large financial institution is maturing its information security program and wants to move from a reactive to a proactive posture. Which of the following initiatives would best support this transition?

Hard
87

A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?

Medium
88

A CISO is establishing an information security governance framework to ensure that security activities are aligned with business strategy. The organization has multiple business units, each with its own IT and security staff. Which of the following is the MOST effective way to ensure ongoing alignment?

Medium
89

Which is a key component of an information security program?

Easy
90

Based on the exhibit, what is the most significant security gap in this configuration?

Medium
91

An organization's information security program is being developed. The CISO needs to ensure that the program's objectives are aligned with the organization's strategic goals. Which of the following is the BEST source of input for defining the security program's objectives?

Easy
92

Which THREE elements are essential for an effective information security governance framework?

Medium
93

A company is implementing a new security program. The CISO wants to ensure alignment with business objectives. Which approach is best?

Medium
94

Which of the following best describes the primary purpose of a security program's governance framework?

Medium
95

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

Hard
96

Which of the following is the PRIMARY purpose of a security program's key performance indicators (KPIs)?

Easy
97

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

Hard
98

A security manager is designing a metrics dashboard for executive management. Which of the following metrics is MOST useful for demonstrating the value of the security program?

Medium
99

You are the CISO of a mid-sized manufacturing company. The company has grown rapidly through acquisitions, and each subsidiary has its own information security program. There is no centralized governance, and recent security incidents have occurred due to inconsistent policies. The board has asked you to create a unified information security program that balances flexibility with control. Each subsidiary has unique operational processes and varying levels of security maturity. You have limited budget and cannot replace all local security teams. Which approach should you take?

Easy
100

A security manager is developing a business case for a new security program. The organization's executives are primarily focused on revenue growth and market expansion. Which approach is MOST effective for securing executive support and funding?

Medium
101

A multinational corporation is designing a global information security program. Which governance structure best ensures consistent security while allowing regional flexibility?

Hard
102

A CISO is presenting the information security program's annual report to the board. The board is concerned about the rising cost of cyber insurance and wants to understand how the program can help reduce premiums. Which of the following actions would MOST directly influence the cost of cyber insurance?

Hard
103

A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?

Hard
104

An organization is establishing a new information security program. The CISO needs to ensure that the program's structure and processes are aligned with the organization's overall business strategy. Which of the following should be the CISO's FIRST step?

Easy
105

An organization has just completed a risk assessment and identified several high-risk vulnerabilities. The security program manager needs to prioritize remediation efforts. Which of the following should be the primary factor in determining priority?

Easy
106

The security team is designing a security awareness program. Which topic should be prioritized FIRST?

Easy
107

Based on the exhibit, which of the following is true about traffic from the internet to the internal network 10.0.0.0/8?

Easy
108

Which metric is most indicative of security program effectiveness?

Easy
109

A healthcare organization's information security program has a policy that requires all ePHI to be encrypted at rest. During a review, the CISO discovers that a legacy application storing ePHI does not support encryption. The application is critical for patient care and cannot be replaced immediately. Which of the following should the CISO do FIRST?

Medium
110

An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?

Medium
111

A global financial services firm has a mature information security program. The CISO wants to ensure that the program's strategic objectives remain aligned with changing business goals, such as a new push into mobile banking. Which of the following is the MOST effective way to achieve this alignment?

Medium
112

An organization is developing its information security program and wants to ensure that security roles and responsibilities are clearly defined and communicated across the enterprise. Which of the following should be established FIRST to achieve this?

Easy
113

A financial services firm has a mature information security program. The Chief Information Security Officer (CISO) is asked by the board to demonstrate that the program is aligned with the organization's strategic objectives. Which of the following is the MOST effective way for the CISO to provide this assurance?

Medium
114

You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?

Hard
115

A financial services firm has completed a risk assessment and identified that its customer-facing web application has a high risk of SQL injection. The CISO must ensure the risk is treated appropriately. Which of the following should be the FIRST action?

Medium
116

A security manager is reviewing the organization's information security strategy and notices that it focuses heavily on technology controls but lacks integration with business processes. Which action should the manager take to improve alignment with business objectives?

Medium
117

A newly appointed CISO is reviewing the existing information security program. The program has many documented policies and procedures, but the CISO notices that they have not been updated in over three years. What should the CISO do FIRST?

Easy
118

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

Hard
119

A CISO is building a new information security program for a multinational corporation. The board has approved a risk appetite statement but has not yet approved a security budget. The CISO must decide which activity to perform FIRST to ensure the program aligns with business objectives. What should the CISO do first?

Hard
120

After a major security incident, the board of directors requests a review of the information security program. Which of the following metrics would be MOST useful to demonstrate the effectiveness of the program over the past year?

Hard
121

A small e-commerce company with 50 employees and limited IT budget is establishing its first formal information security program. The company processes customer payment data and must comply with PCI DSS. The CEO wants to balance security with operational costs. The IT manager proposes investing in a state-of-the-art security information and event management (SIEM) system costing $100,000 annually. The CISO, however, recommends a more phased approach. Considering the company's size, budget constraints, and compliance requirements, what should be the CISO's primary recommendation?

Easy
122

A security manager is tasked with building a business case for a new security program. Which metric is most persuasive to senior management?

Medium
123

Which of the following are essential components of an information security program governance framework? (Select TWO.)

Medium
124

During a security program review, the auditor finds that incident response procedures have not been tested in over two years. What is the MOST significant risk arising from this finding?

Hard
125

An information security manager is developing a program metric to measure the effectiveness of the security awareness training. Which metric is most appropriate?

Medium
126

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Medium
127

A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?

Medium
128

An organization's information security program is based on a risk management framework. Which of the following BEST describes the role of the information security manager in this context?

Medium
129

A multinational organization needs to comply with GDPR and CCPA. What is the best approach for the information security program?

Hard
130

A mid-sized financial services firm has a newly appointed CISO. The board has asked for assurance that the information security program aligns with the organization's strategic goals and risk appetite. The CISO needs to establish a governance structure that provides ongoing oversight and ensures security decisions are made at the right level. Which of the following should the CISO implement FIRST?

Medium
131

A CISO is establishing a security metrics program to measure the effectiveness of the information security program. The CISO wants to include both key goal indicators (KGIs) and key performance indicators (KPIs). Which of the following are examples of KGIs? (Choose two.)

Hard
132

A global financial services firm has a mature information security program with policies, standards, and procedures aligned to ISO/IEC 27001. The CISO is preparing for the annual management review of the program. The board has asked for assurance that the program remains effective as the threat landscape and business strategy evolve. Which activity BEST provides this assurance?

Hard
133

A CISO is establishing an information security governance framework. The organization operates in multiple countries with varying data protection laws. Which of the following should be the PRIMARY consideration when developing security policies?

Easy
134

A financial institution's security program must comply with PCI DSS, GDPR, and SOX. Which approach is MOST efficient to manage overlapping compliance requirements?

Hard
135

An organization has implemented a data classification policy but notices that employees often mark documents as 'internal use only' even when they contain personally identifiable information (PII). Which of the following is the most effective corrective action for the information security program?

Hard
136

During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?

Hard
137

A CISO is reviewing the information security program's performance measurement framework. The organization wants to ensure that the metrics used are effective in demonstrating the program's value to senior management. Which of the following are characteristics of effective security metrics? (Choose two.)

Hard
138

Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?

Easy
139

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Medium

Frequently asked questions

What does the Information Security Program domain cover on the CISM exam?
You must be able to select governance, policy, and program-management actions that align security with business goals and enforce standards. The single most important thing is to identify who owns the risk and the control, then choose the action that improves accountability and proactive risk management.
How many questions are in this domain?
This page lists all 139 Information Security Program questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Security Program questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism security program Practice Questions