CISM Information Security Programme Practice Question
What is the PRIMARY purpose of a security champions program?
⚠ Common exam trap
CISM often tests the collaborative nature of security champions — candidates may select enforcement or audit roles when the correct purpose is advocacy, education, and embedding security into non-security teams.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To embed security advocates in non-security teams to promote security best practices
The primary purpose of a security champions program is to embed security advocates within non-security teams (e.g., development, operations) to promote security best practices (A). Champions are team members with an interest in security who receive additional training and act as liaisons between the security team and their functional teams, scaling security awareness and enabling earlier risk identification without adding headcount.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To embed security advocates in non-security teams to promote security best practices
Why this is correct
Security champions are staff embedded within development, operations, and other non-security teams who advocate secure practises locally. This satisfies the stem's primary purpose by scaling security influence through existing team members rather than centralised security staff alone.
- ✗
To enforce security policies through peer pressure
Why it's wrong here
Peer pressure is not a security control; champions programs build advocacy and secure-by-default guidance, not enforcement, which belongs to policy and management. It tempts because champions do influence colleagues informally, but a program designed to enforce through social pressure would undermine trust and reporting culture.
- ✗
To conduct security audits of other teams
Why it's wrong here
Security champions embed security practise within their own development or operations teams, acting as liaisons who raise awareness and review designs; they do not perform independent audits, which require objectivity the champion role lacks. Auditing is the remit of a separate assurance function, correct when independence from delivery teams is the requirement.
- ✗
To replace the security team in development projects
Why it's wrong here
Champions supplement the security team by embedding expertise in delivery teams; they never assume the security team's accountability for risk decisions or control assurance. It tempts because champions do reduce security-team bottlenecks, but that is capacity augmentation, not replacement of independent security oversight.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.