Courseiva
hardMultiple Choice

CISM Practice Question: During an audit, it was found that the…

During an audit, it was found that the organization's information security policy is not being followed by business units. Which of the following is the MOST effective way for the information security manager to improve compliance?

⚠ Common exam trap

Many candidates choose awareness training (B) as a quick fix, but CISM emphasizes that non-compliance due to policy misalignment requires policy revision, not just more training or enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a policy review committee with business unit representatives to align policy with operational needs.

The most effective way to improve compliance is to align the policy with operational realities by involving business unit representatives in a policy review committee. When policies conflict with business processes, users will bypass them; adjusting the policy to be both secure and practical increases voluntary adherence. This addresses the root cause—policy misalignment—rather than treating symptoms like lack of awareness or enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establish a policy review committee with business unit representatives to align policy with operational needs.

    Why this is correct

    Aligning the policy with operational realities addresses the root cause of non-compliance: business units ignore rules that conflict with how they actually work. A review committee with their representatives secures ownership and practicality, satisfying the stem's requirement to improve compliance rather than merely enforce it.

  • ✗

    Provide additional security awareness training focused on policy requirements.

    Why it's wrong here

    Training addresses awareness, not the underlying reason business units ignore the policy, which is usually competing operational priorities or absent enforcement. It is tempting because awareness is a recognised compliance lever, and it would be correct where staff genuinely do not know the policy requirements.

  • ✗

    Escalate non-compliance to senior management for disciplinary action.

    Why it's wrong here

    Escalation punishes individual breaches but does not address the systemic cause, such as conflicting business incentives or unenforceable policy wording. It is tempting because senior backing carries authority, and it would be correct where business units knowingly disregard policy despite clear ownership and accountability.

  • ✗

    Increase the frequency of automated policy compliance checks.

    Why it's wrong here

    Automated checks detect non-compliance but do not compel business units to change behaviour; detection without consequence leaves the same gap. It is tempting because monitoring provides visibility, and it would be correct where compliance failures stem from undetected drift rather than unwillingness to comply.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.