CISM Information Security Program Practice Question
You are the CISO of a mid-sized financial services firm that processes credit card transactions. The company has recently expanded its operations to include a mobile payment application that stores payment credentials in the cloud. The current information security program was designed primarily for the on-premises environment and has not been updated to address cloud-specific risks. The internal audit team has identified that the cloud service provider (CSP) does not have an independent third-party audit report (e.g., SOC 2) available for review. Additionally, the mobile app development team has been deploying code without formal security review, citing the need for rapid releases to compete in the market. The CEO has expressed concern about the potential for a data breach and has asked you to recommend immediate actions to strengthen the security program while minimizing business disruption. Which of the following should you recommend as the FIRST course of action?
⚠ Common exam trap
The trap here is that candidates often jump to implementing a technical control (like encryption or tokenization) as the immediate fix, but the CISM exam emphasizes that governance and vendor risk management—specifically obtaining independent assurance of the CSP's controls—must come first before deploying compensating technical measures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a detailed security assessment of the cloud service provider's controls and contractually require an annual SOC 2 Type II report.
The correct first course of action because the absence of an independent third-party audit report (e.g., SOC 2 Type II) means the organization has no verified assurance that the cloud service provider (CSP) has adequate security controls in place. As CISO, you must immediately assess the CSP's security posture and contractually mandate a SOC 2 Type II report to gain visibility into the effectiveness of the CSP's controls over time, which is foundational before implementing any compensating technical controls. This aligns with the CISM domain of Information Security Program governance, where vendor risk management and due diligence are critical first steps when expanding into cloud environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all data in transit and at rest using the organization's own encryption keys.
Why it's wrong here
Encrypting data with organisation-managed keys protects confidentiality but does not establish whether the CSP's controls are adequate, leaving the audit finding unresolved. Encryption is appropriate once risk is understood. The first action must obtain assurance over the provider, because due diligence on the CSP precedes selecting technical safeguards.
- ✗
Implement compensating controls such as tokenization for all cardholder data stored in the cloud.
Why it's wrong here
Tokenisation reduces the value of stolen cardholder data but does not verify the CSP's control environment, so the missing SOC 2 report remains unaddressed. Tokenisation is a valid compensating control once risk is assessed. The first action must establish assurance over the provider before controls are chosen.
- ✓
Conduct a detailed security assessment of the cloud service provider's controls and contractually require an annual SOC 2 Type II report.
Why this is correct
Assessing the CSP's controls and contractually mandating an annual SOC 2 Type II report closes the identified assurance gap, since no independent third-party audit currently exists. This addresses the cloud-specific risk first, before tackling the mobile app's absent security reviews.
- ✗
Require the mobile app development team to undergo formal security training and implement a peer review process for all code deployments.
Why it's wrong here
Developer training and peer review address the code-deployment gap but leave the unassessed CSP risk unquantified, so the firm cannot determine whether cardholder data is adequately protected. Training is a valid later remediation. The first action must establish assurance over the CSP, since due diligence precedes accepting residual risk.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.