CISM · domain
Information Security Programme
This domain covers building, governing and operating the information security programme: strategy, frameworks, control prioritisation, budget justification, roles and awareness. Questions are scenario-based, asking you to pick the FIRST or BEST action for a security manager, weighing business alignment, risk, resource limits and defence-in-depth sequencing over technical tooling detail.
Focused practice
Practice Information Security Programme questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Information Security Programme
You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
Selecting control implementation groups and prioritising safeguards against ransomware exposure with limited resources
Applying defence-in-depth sequencing to framework adoption and control prioritisation decisions
Defining the purpose of a security champions programme in embedding security across business teams
Justifying security budget increases using risk reduction and business value metrics
Why learners struggle
Why Information Security Programme questions are commonly missed
RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).
- ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
- ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
- ·MHz vs CL — speed vs latency trade-offs in performance
- ·Single-channel vs dual-channel — bandwidth impact misconception
- ·ECC vs non-ECC — error correction support in servers vs desktops
- ·32-bit vs 64-bit — maximum addressable RAM limit
Watch out for
Common Information Security Programme exam traps
- ▸Choosing the most technically complete control set instead of the FIRST priority given resource constraints and threat exposure.
- ▸Treating security champions as a technical escalation team rather than business-side advocates who extend the security function.
- ▸Justifying budget with fear, compliance mandates or incident anecdotes instead of quantified risk reduction and business alignment.
Question index
All Information Security Programme questions (176)
Click any question to see the full explanation, or start a practice session above.
A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)
Medium2An organization is building a security metrics program. The CISO wants to ensure metrics drive improvement rather than just report status. During a review, the team debates whether a specific metric is a key performance indicator (KPI) or a key risk indicator (KRI). Which characteristic BEST distinguishes a KRI from a KPI in a security program?
Hard3A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)
Medium4A security manager is establishing a security metrics program to report to executive management. Which TWO of the following are characteristics of effective security metrics? (Choose two.)
Hard5A company is designing a third-party risk management (TPRM) program. Which factor should PRIMARILY determine the tier of a vendor?
Medium6An information security manager is designing the reporting structure for the CISO. Which reporting structure is most likely to ensure independence and adequate authority for the security function?
Easy7An organization is implementing a security champions program. Which of the following is the primary benefit of such a program?
Medium8Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)
Medium9A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?
Hard10An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.
Easy11A company is selecting a security control framework. They want a prioritized set of controls that are implementation group-based and address common cyber threats. Which framework best meets these requirements?
Medium12An organization is implementing a security controls framework and needs to prioritize controls for a small business with limited resources. Which implementation group from CIS Controls v8 should be addressed first?
Medium13A global retailer's security programme has grown organically: each region maintains its own policies, risk register, and incident process. The board asks the CISO to align the programme with a recognized standard so performance can be compared across regions. Which action should the CISO take FIRST?
Hard14During third-party risk assessment, a vendor is found to have access to sensitive customer data. The vendor's own supply chain includes a critical fourth-party component. What is the BEST way to address this nth-party risk?
Hard15A newly appointed CISO at a healthcare provider must establish an information security governance structure. Which action should be performed FIRST?
Easy16A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?
Easy17Which TWO of the following are components of a typical vulnerability management program?
Easy18A company is implementing a vendor tiering system for third-party risk management. Which TWO factors should be used to determine the tier of a vendor?
Hard19A multinational retailer is building a new information security programme. The CISO wants to ensure the programme's strategy remains aligned with business objectives as the company expands into new markets. Which action should the CISO take FIRST to establish this alignment?
Medium20An organization with a mature security program is reviewing its budget allocation. The board has asked the CISO to justify a proposed increase. Which of the following provides the STRONGEST justification for the security budget?
Hard21In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)
Easy22A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?
Medium23A company maintains a security scorecard for the executive team. Which metric is MOST appropriate to include as a leading indicator on a one-page dashboard?
Hard24A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)
Hard25An organization uses ISO 27001 Annex A controls. During a risk assessment, they identify a need for a compensating control because the primary control is not feasible. What should the security manager do FIRST?
Hard26A CISO is building a security operations center (SOC). Which TWO of the following are primary functions of a SOC?
Medium27A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?
Medium28A security manager is defining the organization's information security strategy in alignment with business objectives. The organization operates in a highly regulated industry with strict data protection requirements. Which of the following should be the FIRST step in this process?
Medium29A security manager is building a business case for additional security budget. Which THREE justifications are most effective for obtaining executive approval? (Select THREE)
Hard30A newly appointed CISO at a mid-sized financial firm discovers that the information security programme has been operating without a formally approved charter. Business units frequently bypass security review, and the security team lacks authority to enforce policy. Which action should the CISO take FIRST to establish the programme's foundation?
Medium31A security manager is selecting controls for a new application. Which of the following is the BEST approach for prioritization?
Medium32Which of the following is a key objective of implementing a security champions program?
Easy33An information security manager needs to justify a budget increase. Which approach would be MOST effective for gaining executive approval?
Hard34In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?
Medium35A company is developing security metrics to present to the C-suite. Which metric is a leading indicator of security performance?
Medium36A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?
Medium37A security manager is integrating security into the organization's project management lifecycle. A new customer relationship management (CRM) system is being deployed. At which phase should the security team be involved to ensure that security requirements are addressed?
Hard38An organization's CISO reports to the CIO. The CISO is concerned that security initiatives are often deprioritized due to conflicts of interest. Which reporting structure would best address this concern?
Medium39A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?
Medium40A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
Hard41A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?
Hard42An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this principle?
Medium43During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
Hard44Which of the following is a leading indicator for security performance?
Medium45An organization is developing a security scorecard for the CISO. Which of the following is a leading indicator that would be most useful for predicting future security incidents?
Medium46Which THREE elements are essential components of a third-party risk management (TPRM) program? (Select THREE)
Medium47Which TWO of the following are characteristics of a security champions program that contribute to its effectiveness?
Hard48Which security control framework is organized into Implementation Groups (IG1, IG2, IG3) based on organizational risk profile and resources?
Easy49A security architect is designing a defense-in-depth strategy for a financial institution. Which TWO of the following are essential components of a defense-in-depth approach?
Easy50An organization is designing a vendor tiering process for its third-party risk management program. Which TWO factors are MOST appropriate for determining a vendor's risk tier?
Medium51A newly appointed CISO is establishing the information security governance framework for a multinational financial services firm. The board wants assurance that security activities align with business objectives and regulatory obligations. Which action should the CISO take FIRST to establish effective governance?
Medium52Which control family in NIST SP 800-53 addresses the identification and authentication of users?
Easy53A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?
Medium54An organization is implementing a defense-in-depth strategy. Which of the following control combinations BEST exemplifies this approach?
Medium55A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)
Medium56A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?
Medium57In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?
Easy58An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
Hard59A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?
Easy60Which TWO metrics are considered leading indicators for information security program performance?
Medium61A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?
Medium62A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?
Easy63In a vendor tiering system for third-party risk management, which factor is most critical for determining the tier?
Easy64Which THREE of the following are key activities in a third-party risk management (TPRM) program?
Medium65A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?
Hard66A CISO is presenting security metrics to the board. Which of the following metrics would be MOST relevant for a one-page executive dashboard?
Medium67A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
Medium68A security manager is designing a security budget for a mid-sized company. Which TWO of the following are typical components of a security budget?
Hard69A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)
Hard70A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)
Medium71An organization is implementing a vendor risk management program. A vendor that provides cloud-based HR services will have access to employee PII. According to industry best practices, what should be the first step in the vendor lifecycle?
Medium72An organization with a mature security program allocates 12% of its IT budget to security. Which factor is MOST likely to support this level of investment?
Hard73Which THREE of the following are components of a security operations center (SOC)?
Easy74A company wants to establish a security champions program. What is the primary benefit of embedding security champions in development teams?
Hard75What is the PRIMARY purpose of a security champions program?
Easy76A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?
Medium77A healthcare provider's security programme has grown organically, and the CISO now wants to formalize how security requirements are integrated into every new IT project. Which activity should the CISO implement to achieve this?
Easy78A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?
Easy79Which role is primarily responsible for designing and reviewing an organization's security architecture?
Easy80In a security awareness program, which training approach is most appropriate for software developers?
Medium81Which of the following is a leading indicator of security program effectiveness?
Easy82A CISO is designing the security organization for a financial services firm. Which reporting structure is most likely to ensure the independence and authority of the information security function?
Medium83What is the primary function of a Security Operations Center (SOC)?
Easy84A security manager is selecting controls for a new application. Which TWO controls are most important to include in a defense-in-depth strategy? (Select TWO)
Medium85Which of the following is the BEST reporting structure for a CISO to ensure independent oversight and alignment with business strategy?
Easy86An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?
Hard87Which control framework is most appropriate for an organization that wants a prioritized set of controls based on implementation groups (IG1, IG2, IG3)?
Medium88A CISO is preparing an executive dashboard for the board of directors. Which combination of metrics would provide the most meaningful overview of the security programme's effectiveness?
Hard89In a third-party risk management programme, what is the primary purpose of vendor tiering?
Medium90A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?
Hard91Which of the following is the PRIMARY purpose of a security awareness program?
Easy92An organization is selecting security controls from NIST SP 800-53. Which TWO control families are most directly related to access control? (Select TWO)
Medium93During a programme review, a security manager finds that many controls were implemented but no one can demonstrate whether they reduce risk as intended. Which action should be taken to improve the programme's ability to show control effectiveness?
Medium94A financial institution uses CIS Controls v8 and must prioritize implementation. The organization has limited resources and high exposure to ransomware. Which implementation group should be addressed FIRST?
Hard95An organization is implementing a security champions program to improve application security. Which THREE of the following are key success factors for such a program?
Hard96A global retailer's CISO has just completed a security strategy refresh. The board has approved the strategy but asks how they will know whether the programme is delivering the intended risk reduction between annual reviews. Which action should the CISO take FIRST to address the board's request?
Medium97Which control selection framework includes implementation groups (IG1, IG2, IG3) that help organizations prioritize controls based on their risk profile?
Medium98Which role within a security team is primarily responsible for designing and reviewing security architectures to ensure alignment with business requirements and security standards?
Easy99During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?
Medium100Which security team role is primarily responsible for defining and maintaining security architecture standards?
Easy101Which control framework is structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize security controls based on risk?
Easy102A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)
Medium103A security manager is designing an executive security report. Which content is most appropriate for a one-page C-suite dashboard?
Medium104When implementing security controls, which approach ensures that multiple layers of defense are applied so that if one control fails, others compensate?
Easy105A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?
Medium106Which role is primarily responsible for developing and maintaining the organization's security architecture?
Easy107A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?
Hard108An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?
Medium109A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?
Hard110A security architect is selecting controls for an e-commerce platform. Which TWO of the following are examples of compensating controls?
Easy111A security manager is drafting the information security strategy for a multinational retailer. Executive leadership has asked how the strategy should be structured to remain aligned with business objectives over the next three years. Which approach BEST addresses this request?
Medium112In a defence-in-depth strategy, which control is considered a compensating control when a critical application cannot be patched immediately due to operational constraints?
Medium113What is the primary purpose of a vulnerability management program?
Easy114A CISO is evaluating a cloud provider's security posture. Which of the following should be the MOST important consideration in the vendor risk assessment?
Medium115A financial services firm is defining the scope of its information security management system. The CISO must decide which assets and processes fall under the programme's governance. Which criterion should PRIMARILY drive scoping decisions?
Medium116An organization is designing a third-party risk management (TPRM) program. They have identified a vendor that stores sensitive customer data. According to best practices, what should be the minimum requirement for this vendor's contract?
Hard117A company is designing a third-party risk management (TPRM) program. Which THREE of the following are essential components of the ongoing monitoring phase for a critical vendor?
Hard118A retail organisation's security steering committee is prioritising remediation of findings from a recent risk assessment. The CISO must recommend which risk to address FIRST, given limited resources. Which factor should PRIMARILY drive the prioritisation decision?
Hard119An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?
Medium120A software development company is maturing its information security program. The CISO wants to integrate security into the software development lifecycle (SDLC) to reduce vulnerabilities in production. Which of the following is the MOST effective way to achieve this integration?
Hard121An organisation is preparing to adopt a control framework to structure its information security programme. The CISO must select an approach that provides a comprehensive catalogue of controls while allowing tailoring to the organisation's risk profile. Which approach BEST meets this requirement?
Hard122Which of the following is a LEADING indicator of security performance?
Easy123A financial services firm is aligning its information security programme with the organisation's enterprise risk management framework. The CISO must ensure security risk is expressed and escalated consistently with other business risks. Which action BEST achieves this alignment?
Hard124An organization wants to establish a security champions program. What is the primary benefit of embedding security advocates in development teams?
Medium125A SOC analyst receives an alert about a potential malware infection on a critical server. Which step should the analyst take FIRST?
Medium126Which of the following is the PRIMARY benefit of a security champions program?
Easy127A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?
Medium128A software company is defining the roles and responsibilities within its information security programme. The CISO wants clarity on who is accountable for ensuring that security requirements are integrated into the software development lifecycle. Which role should be assigned this accountability?
Easy129A security awareness manager is designing role-based training. Which training is most appropriate for software developers?
Medium130Which of the following is the primary objective of a security champions programme?
Easy131Which of the following is a leading indicator for measuring the effectiveness of a security awareness program?
Medium132An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
Medium133Which of the following is the PRIMARY purpose of a security champions program?
Easy134A newly appointed CISO is reviewing the organization's information security policy framework. The board asks which document should define the organization's overall security objectives and assign responsibilities at the highest level. Which document is MOST appropriate for this purpose?
Easy135Which of the following security team roles is primarily responsible for designing and implementing security solutions to protect an organization's systems and data?
Easy136An organization is defining objectives and key results (OKRs) for the security program. Which TWO of the following are examples of leading indicators that could be used as key results?
Medium137A global manufacturing company has a decentralized information security program. Each region has its own security team and budget. The CISO is concerned about inconsistent security practices and wants to improve the program's maturity. Which of the following is the MOST effective approach to achieve consistency across regions while respecting local autonomy?
Medium138A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
Medium139During an annual programme review, the CISO must demonstrate that the security strategy remains aligned with the organization's objectives. Which input is MOST important to validate that alignment?
Easy140A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)
Hard141An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?
Hard142A financial services firm is updating its information security strategy and needs to align it with the organization's overall business goals. The CISO has been asked to ensure that the security strategy directly supports the achievement of business objectives. Which of the following should be the PRIMARY consideration when aligning the security strategy with business goals?
Medium143Which of the following is a key objective of a Security Operations Center (SOC)?
Easy144In a vendor risk assessment, a third-party vendor will have access to sensitive customer data. According to TPRM best practices, what should the organization do first?
Medium145When designing phishing simulations, which approach best balances user learning and operational disruption?
Hard146A software company's security programme has been in place for two years. The CISO wants to determine whether the programme is achieving its intended outcomes and where improvements are needed. Which approach BEST supports this objective?
Medium147A company is assessing nth-party risk from a critical cloud provider. Which approach should be taken to manage this risk effectively?
Hard148When selecting security controls, a company must prioritize which controls first?
Medium149A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?
Medium150During a security architecture review, the security architect identifies that a new application stores sensitive customer data in plaintext in the database. The application owner argues that performance requirements prevent encryption. What is the most appropriate compensating control to reduce risk?
Hard151A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?
Hard152A CISO is deciding on the organizational structure for the information security team. Which reporting structure is most likely to ensure the security function has sufficient independence and authority?
Easy153An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Medium154An organization is implementing a security champions program. What is the primary purpose of this initiative?
Medium155An organization is implementing CIS Controls v8. Which THREE of the following are implementation groups (IGs) defined in the CIS Controls?
Medium156A security manager is developing a business case for a new security initiative. The organization's leadership is focused on cost reduction. Which of the following approaches is MOST likely to gain approval?
Medium157A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)
Hard158Which TWO are key elements of a security awareness program designed to change employee behavior?
Hard159A security manager is developing a security scorecard for the C-suite. Which combination of metrics would be MOST appropriate for a one-page dashboard?
Medium160An organization is implementing a data security program. Which of the following is the most effective approach to protect sensitive data at rest?
Medium161An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)
Hard162A CISO is building the resource plan for the information security programme and must decide which activities belong to the programme's core management functions rather than to operational security delivery. (Choose two.)
Medium163An information security manager is asked to justify an increase in the security budget. Which approach BEST demonstrates the value of the security program?
Medium164Which TWO of the following are typical components of a security awareness program?
Easy165A CISO is building the programme's risk treatment capability and wants to ensure that identified risks are handled consistently across business units. Which TWO activities are essential components of an effective risk treatment process? (Choose two.)
Hard166Which of the following best describes the role of a security architect in a security program?
Medium167A security manager needs to justify an increase in the security budget. Which approach provides the strongest quantitative justification?
Hard168A mature security program allocates 12% of IT budget to security. Which combination of budget components is most balanced for a program seeking to improve detection and response capabilities?
Hard169An organization's security budget is 8% of the IT budget. Industry benchmarks suggest 10-15% for mature programs. Which of the following should the CISO do FIRST to justify an increase?
Medium170When selecting security controls based on NIST SP 800-53, which control family is MOST directly related to protecting the confidentiality of data?
Medium171Which control family from NIST SP 800-53 is MOST directly associated with ensuring that users have appropriate access rights?
Medium172A company has implemented a security awareness program with quarterly phishing simulations. The click rate has remained at 15% for the past two quarters. What is the most effective next step?
Hard173An organization's third-party risk management program has been in place for two years. Which of the following is the MOST critical action to ensure the program remains effective?
Hard174A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?
Hard175An organization wants to measure the effectiveness of its security awareness programme. Which metric is a leading indicator of improved security culture?
Medium176An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?
HardOther domains
All CISM exam domains
Frequently asked questions
- What does the Information Security Programme domain cover on the CISM exam?
- You must be able to sequence programme work: pick the FIRST or BEST action given risk, resources and business context, and align controls to frameworks like CIS Controls and defence-in-depth. The single most important thing: prioritise by risk and business impact, not by technical completeness.
- How many questions are in this domain?
- This page lists all 176 Information Security Programme questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Information Security Programme questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.