CISM Information Security Program Practice Question
Which document should be reviewed and updated at least annually?
⚠ Common exam trap
CISM often tests the misconception that any security document must be updated annually, but the incident response plan is specifically highlighted because it directly affects response effectiveness and is a common audit finding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response plan
The incident response plan is a living document that must be reviewed and updated at least annually to reflect changes in the organization's environment, threat landscape, and lessons learned from incidents. Regular updates ensure that contact information, escalation procedures, and response strategies remain current and effective. This annual review is a core requirement of frameworks like NIST SP 800-61 and ISO 27001.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vendor contracts
Why it's wrong here
Vendor contracts are reviewed at renewal or when scope, service levels or risk exposure change, not on a fixed annual cycle. Annual review is tempting because contracts do contain security and privacy clauses, but it would be correct only when a specific obligation, regulation or renewal date triggers reassessment.
- ✓
Incident response plan
Why this is correct
The incident response plan documents contacts, roles, escalation paths and procedures that change as systems, personnel and threats evolve. Annual review satisfies the stem's requirement by keeping response actions current and validated, ensuring the plan remains executable during a live incident.
- ✗
Network topology diagram
Why it's wrong here
Network topology diagrams change only when infrastructure changes, so a calendar-driven annual review adds no assurance. Reviewing them is tempting because stale diagrams mislead incident responders, but it would be correct only after architecture changes, not on a fixed yearly schedule.
- ✗
User manuals
Why it's wrong here
User manuals are updated when product functionality changes, not on an annual compliance cycle. Annual review is tempting because manuals do contain operational procedures, but it would be correct only following a software release or process change, not as a scheduled governance activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.