Courseiva
Information Security ProgrammediumMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a gap analysis against the requirements and prioritize remediation.

A gap analysis identifies where controls are missing or insufficient, allowing for a prioritized remediation plan. Option A is wrong because adopting the higher standard may be unnecessary and costly. Option B is wrong because merging without analysis could introduce risks. Option C is wrong because a new framework from scratch may not leverage existing investments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Adopt the more stringent security program from the acquirer across the entire entity.

    Why it's wrong here

    This may not be cost-effective and could disrupt business operations.

  • Merge the two programs by combining all controls from each.

    Why it's wrong here

    This could lead to redundant or conflicting controls without addressing gaps.

  • Implement a completely new framework that meets both regulations.

    Why it's wrong here

    This may ignore existing controls and cause unnecessary disruption.

  • Perform a gap analysis against the requirements and prioritize remediation.

    Why this is correct

    A gap analysis provides a clear picture of what is missing and allows for efficient resource allocation.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.