Courseiva

CISM Information Security Programme Practice Question

What is the PRIMARY purpose of a security champions program?

⚠ Common exam trap

CISM often tests the collaborative nature of security champions — candidates may select enforcement or audit roles when the correct purpose is advocacy, education, and embedding security into non-security teams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To embed security advocates in non-security teams to promote security best practices

The primary purpose of a security champions program is to embed security advocates within non-security teams (e.g., development, operations) to promote security best practices (A). Champions are team members with an interest in security who receive additional training and act as liaisons between the security team and their functional teams, scaling security awareness and enabling earlier risk identification without adding headcount.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To embed security advocates in non-security teams to promote security best practices

    Why this is correct

    Security champions are staff embedded within development, operations, and other non-security teams who advocate secure practises locally. This satisfies the stem's primary purpose by scaling security influence through existing team members rather than centralised security staff alone.

  • ✗

    To enforce security policies through peer pressure

    Why it's wrong here

    Peer pressure is not a security control; champions programs build advocacy and secure-by-default guidance, not enforcement, which belongs to policy and management. It tempts because champions do influence colleagues informally, but a program designed to enforce through social pressure would undermine trust and reporting culture.

  • ✗

    To conduct security audits of other teams

    Why it's wrong here

    Security champions embed security practise within their own development or operations teams, acting as liaisons who raise awareness and review designs; they do not perform independent audits, which require objectivity the champion role lacks. Auditing is the remit of a separate assurance function, correct when independence from delivery teams is the requirement.

  • ✗

    To replace the security team in development projects

    Why it's wrong here

    Champions supplement the security team by embedding expertise in delivery teams; they never assume the security team's accountability for risk decisions or control assurance. It tempts because champions do reduce security-team bottlenecks, but that is capacity augmentation, not replacement of independent security oversight.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.