hardMultiple ChoiceObjective-mapped
CISSP Practice Question: Merging with another and must integrate security…
A company is merging with another and must integrate security policies. What is the first step?
⚠ Common exam trap
Many candidates assume the immediate goal is to enforce the highest security level (Option D), but CISSP emphasizes that effective security management requires a structured, risk-based approach starting with assessment, not unilateral adoption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a gap analysis
The first step in integrating security policies during a merger is to conduct a gap analysis. This systematically compares the existing policies, controls, and compliance requirements of both organizations against each other and against relevant standards (e.g., ISO 27001, NIST SP 800-53). Without understanding the current state and discrepancies, any subsequent policy creation, training, or adoption of a stricter policy would be uninformed and likely ineffective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a gap analysis
Why this is correct
Conducting a gap analysis is the foundational first step in security integration during a merger. It systematically identifies discrepancies between the merging entities' current security postures, policies, controls, and compliance requirements. This comprehensive assessment provides the critical data needed to understand the combined risk landscape and inform the development of a unified, effective security strategy.
- ✗
Train all employees
Why it's wrong here
Training all employees prematurely, before a unified security policy and integrated procedures are finalized, is inefficient and potentially counterproductive. Effective security awareness and specialized training programs must be based on established, approved policies and the specific operational environment of the merged entity. Without clear guidelines, training efforts risk disseminating inconsistent or outdated information, leading to confusion and non-compliance.
- ✗
Create a new policy
Why it's wrong here
Creating a new security policy without first conducting a thorough gap analysis is a reactive and uninformed approach. A robust policy framework must be built upon a clear understanding of both organizations' existing controls, identified vulnerabilities, and regulatory obligations. Developing policies in isolation risks overlooking critical security requirements, failing to address specific risks, or creating unmanageable operational burdens for the combined entity.
- ✗
Adopt the stricter policy
Why it's wrong here
Simply adopting the stricter security policy from one of the merging companies, while seemingly straightforward, often fails to achieve optimal security integration. This approach can introduce unnecessary operational complexities, alienate employees from the less strict organization, and may not address unique risks or compliance needs present in the other entity. A tailored, harmonized policy, informed by a comprehensive analysis, is generally more effective and promotes better organizational buy-in.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.