CISM Information Security Program Development 1 — Questions and Answers
Question 1: When developing an information security program, a CISM should FIRST:
- Procure security tools and technologies
- Define the security program's scope and objectives based on business needs (Correct answer)
- Hire additional security analysts
- Conduct employee phishing simulations
Correct answer: Define the security program's scope and objectives based on business needs
Defining the scope and objectives aligned to business needs ensures the security program is purposeful, relevant, and capable of gaining organizational support.
Question 2: Which of the following is MOST critical to the long-term success of an information security program?
- Use of the latest security technologies
- Ongoing executive sponsorship and adequate resourcing (Correct answer)
- 100% employee compliance with all policies
- Elimination of all third-party relationships
Correct answer: Ongoing executive sponsorship and adequate resourcing
Sustained executive sponsorship and adequate resources are the most critical success factors for a security program's long-term effectiveness.
Question 3: A CISM is selecting security controls for a new information security program. Controls should PRIMARILY be selected based on:
- Vendor recommendations and marketing materials
- Risk assessment results and business requirements (Correct answer)
- What peer organizations have implemented
- The lowest acquisition and implementation cost
Correct answer: Risk assessment results and business requirements
Control selection should be driven by risk assessment results and business requirements to ensure controls address actual risks and support business operations.
Question 4: Which of the following BEST describes the purpose of a security awareness training program?
- To replace technical security controls
- To educate employees about threats and their role in protecting information (Correct answer)
- To satisfy regulatory requirements only
- To test employees with unannounced phishing attacks
Correct answer: To educate employees about threats and their role in protecting information
Security awareness training educates employees about information security threats and their individual responsibilities in protecting organizational assets.
Question 5: A CISM is developing a security roadmap. The roadmap should be aligned to:
- The latest cybersecurity threat intelligence reports
- The organization's strategic business plan and risk tolerance (Correct answer)
- Industry peer benchmarks and best practices only
- The IT department's annual budget cycle
Correct answer: The organization's strategic business plan and risk tolerance
A security roadmap must align to the organization's strategic business plan and risk tolerance to ensure security investments support business goals.
Question 6: Which metric is MOST useful for measuring the effectiveness of a security awareness program?
- Number of employees who completed training modules
- Reduction in security incidents attributable to human error over time (Correct answer)
- Total cost of the training program delivery
- Number of policies employees acknowledged
Correct answer: Reduction in security incidents attributable to human error over time
Measuring the reduction in human-error-related incidents over time provides evidence of behavior change, the true goal of awareness training.
When developing an information security program, a CISM should FIRST: