Courseiva

CISM · domain

Information Security Programme

This domain covers building, governing and operating the information security programme: strategy, frameworks, control prioritisation, budget justification, roles and awareness. Questions are scenario-based, asking you to pick the FIRST or BEST action for a security manager, weighing business alignment, risk, resource limits and defence-in-depth sequencing over technical tooling detail.

176 questions41 easy83 medium52 hard

Focused practice

Practice Information Security Programme questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Security Programme

You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.

Selecting control implementation groups and prioritising safeguards against ransomware exposure with limited resources

Applying defence-in-depth sequencing to framework adoption and control prioritisation decisions

Defining the purpose of a security champions programme in embedding security across business teams

Justifying security budget increases using risk reduction and business value metrics

Why learners struggle

Why Information Security Programme questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Information Security Programme exam traps

  • ▸Choosing the most technically complete control set instead of the FIRST priority given resource constraints and threat exposure.
  • ▸Treating security champions as a technical escalation team rather than business-side advocates who extend the security function.
  • ▸Justifying budget with fear, compliance mandates or incident anecdotes instead of quantified risk reduction and business alignment.

Question index

All Information Security Programme questions (176)

Click any question to see the full explanation, or start a practice session above.

1

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Medium
2

An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?

Hard
3

A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)

Medium
4

A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)

Hard
5

A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?

Medium
6

An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?

Easy
7

An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?

Medium
8

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Medium
9

A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?

Hard
10

An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.

Easy
11

A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?

Medium
12

An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?

Medium
13

A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?

Hard
14

During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?

Hard
15

A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?

Easy
16

A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?

Easy
17

Which TWO of the following are components of a typical vulnerability management program?

Easy
18

A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?

Hard
19

A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?

Medium
20

An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?

Hard
21

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Easy
22

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

Medium
23

A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?

Hard
24

A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)

Hard
25

An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?

Hard
26

A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?

Medium
27

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

Medium
28

A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?

Medium
29

A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)

Hard
30

A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?

Medium
31

A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?

Medium
32

Which of the following is a key objective of implementing a security champions program?

Easy
33

An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?

Hard
34

In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?

Medium
35

A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?

Medium
36

A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?

Medium
37

A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?

Hard
38

An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?

Medium
39

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

Medium
40

A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?

Hard
41

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

Hard
42

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?

Medium
43

During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?

Hard
44

Which of the following is a leading indicator for security performance?

Medium
45

An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?

Medium
46

Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)

Medium
47

Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?

Hard
48

Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?

Easy
49

A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?

Easy
50

An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?

Medium
51

A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?

Medium
52

Which control family in NIST SP 800-53 addresses the identification and authentication of users?

Easy
53

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

Medium
54

An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?

Medium
55

A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)

Medium
56

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

Medium
57

In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?

Easy
58

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Hard
59

A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?

Easy
60

Which TWO metrics are considered leading indicators for information security program performance?

Medium
61

A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?

Medium
62

A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?

Easy
63

In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?

Easy
64

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

Medium
65

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

Hard
66

A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?

Medium
67

A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?

Medium
68

A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?

Hard
69

A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)

Hard
70

A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)

Medium
71

An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?

Medium
72

An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?

Hard
73

Which THREE of the following are components of a security operations center (SOC)?

Easy
74

A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?

Hard
75

What is the PRIMARY purpose of a security champions program?

Easy
76

A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?

Medium
77

A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?

Easy
78

A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?

Easy
79

Which role is primarily responsible for designing and reviewing an organization's security architecture?

Easy
80

In a security awareness program, which training approach is most appropriate for software developers?

Medium
81

Which of the following is a leading indicator of security program effectiveness?

Easy
82

A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?

Medium
83

What is the primary function of a Security Operations Center (SOC)?

Easy
84

A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)

Medium
85

Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?

Easy
86

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

Hard
87

Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?

Medium
88

A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?

Hard
89

In a third-party risk management programme, what is the primary purpose of vendor tiering?

Medium
90

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Hard
91

Which of the following is the PRIMARY purpose of a security awareness program?

Easy
92

An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)

Medium
93

During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?

Medium
94

A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?

Hard
95

An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?

Hard
96

A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?

Medium
97

Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?

Medium
98

Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?

Easy
99

During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?

Medium
100

Which security team role is primarily responsible for defining and maintaining security architecture standards?

Easy
101

Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?

Easy
102

A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)

Medium
103

A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?

Medium
104

When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?

Easy
105

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Medium
106

Which role is primarily responsible for developing and maintaining the organization's security architecture?

Easy
107

A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?

Hard
108

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

Medium
109

A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?

Hard
110

A security architect is selecting controls for an e-commerce platform. Which TWO of the following are examples of compensating controls?

Easy
111

A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?

Medium
112

In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?

Medium
113

What is the primary purpose of a vulnerability management program?

Easy
114

A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?

Medium
115

A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?

Medium
116

An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?

Hard
117

A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?

Hard
118

A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?

Hard
119

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

Medium
120

A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?

Hard
121

An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?

Hard
122

Which of the following is a LEADING indicator of security performance?

Easy
123

A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?

Hard
124

An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?

Medium
125

A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?

Medium
126

Which of the following is the PRIMARY benefit of a security champions program?

Easy
127

A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?

Medium
128

A software company is defining the roles and responsibilities within its information security programme. The CISO wants clarity on who is accountable for ensuring that security requirements are integrated into the software development lifecycle. Which role should be assigned this accountability?

Easy
129

A security awareness manager is designing role-based training. Which training is most appropriate for software developers?

Medium
130

Which of the following is the primary objective of a security champions programme?

Easy
131

Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?

Medium
132

An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?

Medium
133

Which of the following is the PRIMARY purpose of a security champions program?

Easy
134

A newly appointed CISO is reviewing the organization's information security policy framework. The board asks which document should define the organization's overall security objectives and assign responsibilities at the highest level. Which document is MOST appropriate for this purpose?

Easy
135

Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?

Easy
136

An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?

Medium
137

A global manufacturing company has a decentralized information security program. Each region has its own security team and budget. The CISO is concerned about inconsistent security practices and wants to improve the program's maturity. Which of the following is the MOST effective approach to achieve consistency across regions while respecting local autonomy?

Medium
138

A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?

Medium
139

During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?

Easy
140

A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)

Hard
141

An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?

Hard
142

A financial services firm is updating its information security strategy and needs to align it with the organization's overall business goals. The CISO has been asked to ensure that the security strategy directly supports the achievement of business objectives. Which of the following should be the PRIMARY consideration when aligning the security strategy with business goals?

Medium
143

Which of the following is a key objective of a Security Operations Center (SOC)?

Easy
144

In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?

Medium
145

When designing phishing simulations, which approach best balances user learning and operational disruption?

Hard
146

A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?

Medium
147

A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?

Hard
148

When selecting security controls, a company must prioritize which controls first?

Medium
149

A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?

Medium
150

During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?

Hard
151

A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?

Hard
152

A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?

Easy
153

An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?

Medium
154

An organization is implementing a security champions program. What is the primary purpose of this initiative?

Medium
155

An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?

Medium
156

A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?

Medium
157

A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)

Hard
158

Which TWO are key elements of a security awareness program designed to change employee behavior?

Hard
159

A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?

Medium
160

An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?

Medium
161

An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)

Hard
162

A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)

Medium
163

An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?

Medium
164

Which TWO of the following are typical components of a security awareness program?

Easy
165

A CISO is building the programme's risk treatment capability and wants to ensure that identified risks are handled consistently across business units. Which TWO activities are essential components of an effective risk treatment process? (Choose two.)

Hard
166

Which of the following best describes the role of a security architect in a security program?

Medium
167

A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?

Hard
168

A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?

Hard
169

An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?

Medium
170

When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?

Medium
171

Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?

Medium
172

A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?

Hard
173

An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?

Hard
174

A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?

Hard
175

An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?

Medium
176

An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?

Hard

Frequently asked questions

What does the Information Security Programme domain cover on the CISM exam?
You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
How many questions are in this domain?
This page lists all 176 Information Security Programme questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Security Programme questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism security programme Practice Questions