Courseiva

CISM Information Security Programme Practice Question

During an annual programme review, a CISO finds that security policies exist but employees across regions interpret and apply them inconsistently. Auditors have flagged this as a governance weakness. Which action should the CISO take to strengthen policy governance?

⚠ Common exam trap

The trap here is assuming that awareness attestation or policy consolidation fixes inconsistency, when the real gap is missing lifecycle ownership and exception governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a formal policy lifecycle process with defined ownership, review cycles, exception handling, and communication requirements.

Inconsistent policy application is a governance problem best resolved by instituting a formal policy lifecycle covering ownership, review cadence, exception management, and communication. This creates accountability and an auditable process that auditors expect. Collapsing policies, decentralizing authority without oversight, or relying solely on attestation each fails to address the structural causes of inconsistent interpretation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delegate full policy authority to each regional security manager and remove central oversight.

    Why it's wrong here

    Delegating authority without central oversight accelerates divergence, since each region would define requirements differently and no enterprise baseline would remain. The audit finding concerns inconsistent application, and removing central governance deepens that problem. Regional managers still need enterprise policy as a foundation, with local adaptation only where law or operations require it under a controlled exception process.

  • ✓

    Establish a formal policy lifecycle process with defined ownership, review cycles, exception handling, and communication requirements.

    Why this is correct

    Inconsistent interpretation usually stems from the absence of a managed lifecycle: no clear owner, no scheduled reviews, no defined exception path, and no structured communication. A formal lifecycle process assigns accountability, standardizes how policies are approved and updated, and ensures exceptions are documented and risk-accepted. This directly addresses the governance weakness auditors identified and creates an auditable trail of policy management.

  • ✗

    Require annual attestation from all employees that they have read and understood every security policy document.

    Why it's wrong here

    Attestation confirms receipt, not consistent interpretation or application. Employees can sign without changing behaviour, and the underlying issues of ownership, review, and exception handling remain untouched. While attestation can be part of a communication programme, it does not by itself resolve the governance weakness auditors flagged, so it cannot be the primary corrective action.

  • ✗

    Replace all existing policies with a single short acceptable use statement signed annually by every employee.

    Why it's wrong here

    Consolidating everything into one brief statement removes the detailed control requirements that regions currently apply, worsening inconsistency rather than fixing it. Signing an acceptable use statement confirms awareness but does not establish ownership, review cycles, or exception handling. This approach reduces governance maturity and would likely generate new audit findings about missing policy coverage.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.