mediumMultiple Choice
CISM Practice Question: During a merger, the acquiring company's CISO…
During a merger, the acquiring company's CISO must integrate the security governance of the target company. The target company has no formal security governance. What is the FIRST step the CISO should take?
⚠ Common exam trap
ISACA often tests the principle that governance integration must begin with understanding the current state (risk assessment) rather than jumping to policy alignment or implementation, which is a common mistake candidates make by assuming immediate enforcement is the first step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a comprehensive risk assessment of the target company's security posture.
Without a formal security governance structure, the CISO must first understand the target company's current security posture through a comprehensive risk assessment. This step identifies vulnerabilities, threats, and gaps in controls, providing the baseline data needed to prioritize integration efforts and align with the acquirer's governance framework. Skipping this assessment risks implementing policies that are irrelevant or ineffective against the target's actual risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a security awareness training for the target company's employees.
Why it's wrong here
Awareness training addresses employee behaviour, not the missing governance structures, so it cannot establish the policies, roles and oversight the target lacks. It is tempting because training is a familiar early security activity, and would be correct once a framework and supporting policies are in place.
- ✓
Perform a comprehensive risk assessment of the target company's security posture.
Why this is correct
Without a formal governance framework, the CISO cannot know what controls, gaps or exposures exist. A comprehensive risk assessment of the target's security posture establishes that baseline, informing subsequent governance design, policy alignment and remediation priorities.
- ✗
Align the target company's security policies with the acquirer's policies.
Why it's wrong here
Aligning policies presumes a baseline exists to align from; the target has no formal governance, so there is nothing to map against and gaps stay unidentified. It is tempting because policy harmonisation is the visible end goal, and would be correct after an assessment defines the current state.
- ✗
Implement the acquirer's security governance framework immediately.
Why it's wrong here
Imposing the acquirer's framework immediately skips assessing the target's existing controls, risks and gaps, so integration decisions lack evidence. It is tempting because rapid standardisation appears efficient, and would be correct once a risk assessment has established what the target actually needs.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.