CISM Information Security Program Practice Question
You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?
⚠ Common exam trap
The trap here is that candidates often jump to implementing a technical control (like encryption or tokenization) as the immediate fix, but the CISM exam emphasizes that governance and vendor risk management—specifically obtaining independent assurance of the CSP's controls—must come first before deploying compensating technical measures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a detailed security assessment of the cloud service provider's controls and contractually require an annual SOC 2 Type II report.
The correct first course of action because the absence of an independent third-party audit report (e.g., SOC 2 Type II) means the organization has no verified assurance that the cloud service provider (CSP) has adequate security controls in place. As CISO, you must immediately assess the CSP's security posture and contractually mandate a SOC 2 Type II report to gain visibility into the effectiveness of the CSP's controls over time, which is foundational before implementing any compensating technical controls. This aligns with the CISM domain of Information Security Program governance, where vendor risk management and due diligence are critical first steps when expanding into cloud environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all data in transit and at rest using the organization's own encryption keys.
Why it's wrong here
Encryption is a control, but without assessing the CSP's overall security, data could still be at risk.
- ✗
Implement compensating controls such as tokenization for all cardholder data stored in the cloud.
Why it's wrong here
Compensating controls are a secondary measure; the primary need is to assess the CSP's security posture.
- ✓
Conduct a detailed security assessment of the cloud service provider's controls and contractually require an annual SOC 2 Type II report.
Why this is correct
This directly addresses the gap in oversight and provides assurance over the CSP's controls.
- ✗
Require the mobile app development team to undergo formal security training and implement a peer review process for all code deployments.
Why it's wrong here
While important for secure development, this does not address the immediate cloud risk.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.