Courseiva
mediumMultiple Choice

CISM Practice Question: The IT governance officer at a regional bank with…

You are the IT governance officer at a regional bank with 1,200 employees. The bank has a security policy that requires annual security awareness training for all staff. However, the compliance rate is only 60%. The board is concerned about regulatory risk and wants to improve compliance. The current training is a generic online module that takes 30 minutes to complete. Employees complain that the training is boring and not relevant to their roles. The training is managed by the HR department, which sends reminders but does not enforce consequences. Which of the following is the BEST course of action to improve training compliance and governance?

⚠ Common exam trap

The trap here is that candidates often mistake tracking (Option C) for enforcement, failing to recognize that governance requires both visibility and consequences to drive compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Redesign the training to be role-specific and mandate completion in the security governance framework with consequences for non-compliance.

It addresses both the root cause (irrelevant training) and the governance gap (lack of enforcement). By redesigning training to be role-specific, employees see direct relevance, which improves engagement and retention. Mandating completion within the security governance framework and attaching consequences (e.g., access revocation) creates accountability, directly driving compliance from 60% toward the board's target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outsource the training to a third-party provider.

    Why it's wrong here

    Outsourcing does not inherently improve compliance if content and enforcement are not improved.

  • ✗

    Increase the frequency of reminder emails from monthly to weekly.

    Why it's wrong here

    More frequent reminders intensify a control already shown ineffective; the stem states HR sends reminders without enforcement, so volume is not the limiting factor. It tempts because cadence is a cheap, visible lever, and it would be right if employees were simply forgetting deadlines.

  • ✗

    Implement a learning management system (LMS) to track completion.

    Why it's wrong here

    An LMS only records completion; it does not address the disengagement and absent enforcement driving the 60% rate, so compliance would remain unchanged. It tempts because tracking is a genuine governance control, and it would be right if the gap were visibility rather than motivation.

  • ✓

    Redesign the training to be role-specific and mandate completion in the security governance framework with consequences for non-compliance.

    Why this is correct

    Mandating completion within the security governance framework with consequences directly addresses the enforcement gap left by HR's reminder-only approach, satisfying the board's regulatory risk concern. Role-specific redesign tackles the relevance complaint driving the 60% rate, embedding accountability rather than relying on generic annual modules.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.