Courseiva

CISM Information Security Programme Practice Question

Which of the following is the PRIMARY benefit of a security champions program?

⚠ Common exam trap

CISM often tests the difference between cultural initiatives and technical controls; candidates may confuse the champions program with automation or training reduction, missing its core purpose of embedding advocates in business units.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Embedding security advocates in business units

A security champions program embeds security-minded individuals within business units to act as liaisons between the security team and the business. This distributes security responsibility and promotes a security culture, enabling early risk identification and faster remediation. The primary benefit is not reducing training, automating testing, or eliminating third-party risks, but rather integrating security advocates into development and operational teams.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reducing the need for security awareness training

    Why it's wrong here

    A champions program embeds security advocates within delivery teams to extend reach and culture, not to replace formal awareness training, which remains a compliance and baseline requirement. It is tempting because champions do reinforce awareness messaging locally, and in a small organisation with mature training already in place, champions could supplement it.

  • ✓

    Embedding security advocates in business units

    Why this is correct

    Placing advocates within business units distributes security ownership beyond the central team, so risks are identified and addressed where work actually happens. This satisfies the primary benefit of extending reach and embedding accountability into daily business processes rather than relying solely on periodic centralised training.

  • ✗

    Automating security testing

    Why it's wrong here

    Champions are people who promote secure behaviours and act as liaisons; automating security testing is the function of SAST, DAST and CI/CD pipeline tooling, not a human network. It tempts because champions often help teams adopt scanning tools, but in a DevSecOps tooling initiative that adoption support would be the correct fit.

  • ✗

    Eliminating third-party risks

    Why it's wrong here

    Third-party risk is governed through vendor assessments, contractual controls and supply chain due diligence; an internal champions network cannot eliminate external provider exposure. It tempts because champions can raise supplier security awareness internally, which would be the right choice when the goal is cultural vigilance rather than risk elimination.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.