Courseiva
mediumMultiple ChoiceObjective-mapped

CISM Practice Question: During a merger, the acquiring company's CISO…

During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?

⚠ Common exam trap

ISACA often tests the principle that governance integration must begin with understanding the current state (risk assessment) rather than jumping to policy alignment or implementation, which is a common mistake candidates make by assuming immediate enforcement is the first step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a comprehensive risk assessment of the target company's security posture.

Without a formal security governance structure, the CISO must first understand the target company's current security posture through a comprehensive risk assessment. This step identifies vulnerabilities, threats, and gaps in controls, providing the baseline data needed to prioritize integration efforts and align with the acquirer's governance framework. Skipping this assessment risks implementing policies that are irrelevant or ineffective against the target's actual risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a security awareness training for the target company's employees.

    Why it's wrong here

    Necessary but not the first step; assessment should come first.

  • Perform a comprehensive risk assessment of the target company's security posture.

    Why this is correct

    Initial assessment informs integration strategy.

  • Align the target company's security policies with the acquirer's policies.

    Why it's wrong here

    Premature without understanding the target's environment.

  • Implement the acquirer's security governance framework immediately.

    Why it's wrong here

    Imposition without assessment can lead to failure.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.