Courseiva
Information Security ProgrammediumMatchingObjective-mapped

CISM Information Security Program Practice Question

Match each CISM domain to its focus area.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Establish and maintain a framework to align security with business objectives

Identify and manage information risk to achieve business objectives

Design and implement a security program to manage risk

Plan and manage the incident response process

Oversee and improve the security program's performance

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Information Security Governance: Establishing and maintaining a framework to ensure information security strategies are aligned with business objectives.

The CISM domains are: Governance (strategy alignment), Risk Management (risk identification and management), Program Development (design and implementation), and Incident Management (detection and response). Common confusions include swapping program development with governance and incident management with risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Information Security Governance: Establishing and maintaining a framework to ensure information security strategies are aligned with business objectives.

    Why this is correct

    This is the correct focus of Information Security Governance as per CISM.

  • Information Risk Management: Identifying and managing information risks to achieve business objectives.

    Why this is correct

    This is the correct focus of Information Risk Management as per CISM.

  • Information Security Program Development and Management: Designing, implementing, and managing the information security program.

    Why this is correct

    This is the correct focus of Information Security Program Development and Management as per CISM.

  • Information Security Incident Management: Planning, establishing, and managing the capability to detect, respond to, and recover from incidents.

    Why this is correct

    This is the correct focus of Information Security Incident Management as per CISM.

  • Information Security Governance: Designing and implementing security solutions.

    Why it's wrong here

    Incorrect — this describes Information Security Program Development and Management, not Governance.

  • Information Risk Management: Responding to security incidents.

    Why it's wrong here

    Incorrect — this describes Information Security Incident Management, not Risk Management.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.