CISM Information Security Program Practice Question
You are the CISO of a retail company that is planning to implement a new e-commerce platform. The information security program currently consists of a set of high-level policies, but there are no detailed standards or guidelines for secure development. The development team uses agile methodologies and is accustomed to rapid releases. They have resisted security reviews in the past, citing delays. You need to integrate security into the development lifecycle without causing friction. The company's risk appetite is moderate; they accept some risk for speed but not if it leads to major breaches. The board expects you to manage this risk effectively. Which approach should you take?
⚠ Common exam trap
CISM often tests the misconception that adding a mandatory security gate or a separate review team is the best way to integrate security, when the exam favors enabling and embedding security within existing agile teams.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a security champion to each development team and create a lightweight secure coding checklist.
Assigning a security champion to each development team and providing a lightweight secure coding checklist integrates security into agile workflows without imposing heavy gates. It leverages existing team structures, keeps friction low, and aligns with a moderate risk appetite by embedding security early rather than blocking releases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide annual security training to all developers.
Why it's wrong here
Annual training builds awareness but does not embed controls into agile sprints, so insecure code still reaches release. It appeals as low-friction and cheap. Integrating security activities — threat modelling, secure coding, automated scanning — into each sprint is correct when detailed standards are absent and rapid releases are required.
- ✓
Assign a security champion to each development team and create a lightweight secure coding checklist.
Why this is correct
Embedding a security champion within each agile team and supplying a lightweight secure coding checklist integrates controls directly into rapid sprints, satisfying the moderate risk appetite and the constraint of avoiding the friction that formal security reviews previously caused.
- ✗
Establish a separate security team that reviews all code after development is complete.
Why it's wrong here
Post-development review places security after code is written, forcing rework that conflicts with agile cadence and the team's resistance to delays. It appeals as independent assurance. Embedding security practices within each sprint is correct; retrospective review cannot shape design decisions made earlier in the lifecycle.
- ✗
Implement a mandatory security gate before each release, requiring a full security review.
Why it's wrong here
A full review before every release creates the delays developers resisted and cannot keep pace with rapid iterations. It appeals as strong assurance. Lightweight, automated checks embedded per sprint are correct; a mandatory gate treats security as a final checkpoint rather than a continuous, integrated activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.