CoStudy

HomeCertificationsCISM › Information Security Program — Development and Resources

Information Security Program — Development and Resources — CISM practice questions

66 multiple-choice questions and 32 flashcards on Information Security Program — Development and Resources, about 17% of the CISM bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Information Security Program — Development and Resources is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 66 of the bank's 400 multiple-choice questions — roughly 17% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Information Security Program — Development and Resources practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

Which factor is MOST important when deciding whether to outsource a security capability?

  1. The prevailing market rate for the equivalent internal roles
  2. Whether the capability is available as a managed service
  3. Whether it requires deep enterprise context to perform well
  4. Whether the enterprise has physical space for additional staff

Answer: C — Whether it requires deep enterprise context to perform well

C) Correct - capabilities that depend on intimate knowledge of the business, its systems and its people degrade when moved outside, while commoditised, context-light capabilities transfer well. A) Cost comparison matters but choosing on price alone routinely outsources the wrong things. B) Market availability describes what is possible, not what is wise. D) Accommodation is a logistical consideration well below the sourcing decision.

A maturity assessment is MOST useful when:

  1. Performed by the security team alone, without business participation
  2. Compared only against the organization's own score from the prior year
  3. Reported to the board as a single composite maturity number quarterly
  4. Used to find gaps against a risk-appetite target and fund a roadmap

Answer: D — Used to find gaps against a risk-appetite target and fund a roadmap

D is the key: maturity has value only when it drives prioritized investment against a risk-based target. A misses business context. B has no external reference. C loses the detail needed to decide anything.

A newly hired security manager is asked to build an information security programme from scratch. The FIRST activity should be to:

  1. select a control framework and begin a gap assessment against it
  2. understand the business objectives, obligations and risk appetite
  3. recruit the core security team so that work can begin in parallel
  4. deploy baseline technical controls on the most exposed systems

Answer: B — understand the business objectives, obligations and risk appetite

B) Correct - a programme is an instrument for delivering business outcomes, so its objectives must be derived from what the enterprise is trying to achieve and what it is obliged to do. A) Framework selection before understanding requirements produces a checklist programme that is expensive and poorly aligned. C) Hiring precedes knowing what capabilities are needed and locks in the wrong skill mix. D) Deploying controls first is activity without direction and creates commitments that are hard to unwind.

A compensating control is appropriate when:

  1. The primary control is available and preferred by the control owner
  2. A vendor recommends its own product in place of the specified control
  3. The auditor is unavailable to test the primary control this cycle
  4. The primary control is infeasible and the alternative is equivalent

Answer: D — The primary control is infeasible and the alternative is equivalent

D is the key: a compensating control is a deliberate substitute that must demonstrate equivalent risk reduction and be approved. A removes the reason to compensate. B is vendor-led control selection. C confuses assurance scheduling with control design.

The PRIMARY objective of an information security programme is to:

  1. Implement every control listed in the ISO/IEC 27002:2022 guidance catalogue in full
  2. Deliver capabilities that achieve the strategy and protect value within appetite
  3. Achieve and sustain one hundred per cent patch compliance across the estate
  4. Pass every internal and external audit conducted during the financial year

Answer: B — Deliver capabilities that achieve the strategy and protect value within appetite

B ties the programme to outcomes: it exists to build and sustain the capabilities that deliver the security strategy and protect business value within the risk appetite that leadership has set. A treats a guidance catalogue as a target, ignoring that controls are selected by risk. C sets an absolute technical metric that consumes resource with no reference to criticality. D makes assurance the objective, so the programme optimises for evidence rather than exposure.

Cryptography governance is BEST exercised through:

  1. Allowing each delivery team to select the algorithms suited to its own workload
  2. Enterprise standards for algorithms, key length, lifecycle and key ownership
  3. Outsourcing all encryption and key handling to the cloud service providers
  4. Avoiding asymmetric cryptography in favour of symmetric schemes throughout

Answer: B — Enterprise standards for algorithms, key length, lifecycle and key ownership

B is governance in the proper sense: an approved standard fixes acceptable algorithms and key lengths, defines the key lifecycle and names the roles accountable for it, which gives the organisation one place to change when guidance moves, as it is doing with the migration to post-quantum standards. A produces drift toward whatever each team finds convenient. C outsources execution but not accountability for the keys. D discards a capability that key exchange and digital signature depend on.

An enterprise reports mean time to remediate vulnerabilities as a single enterprise-wide average. The MOST useful improvement would be to:

  1. report the median instead of the mean to reduce outlier distortion
  2. increase the reporting frequency from monthly to weekly
  3. add the total number of vulnerabilities remediated to the same chart
  4. segment the measure by asset criticality and severity

Answer: D — segment the measure by asset criticality and severity

D) Correct - a single average lets fast fixes on trivial systems mask slow remediation on critical ones, so segmentation is what makes the number decision-relevant. A) The median handles outliers but still conflates critical and trivial assets. B) More frequent reporting of an uninformative aggregate simply produces it more often. C) Adding volume alongside duration compounds activity counting rather than clarifying exposure.

An enterprise processes card payments and must design controls accordingly. Which is the MOST appropriate first step in applying the payment card standard?

  1. Encrypt all databases across the whole of the enterprise estate
  2. Engage a qualified assessor to begin the annual assessment work
  3. Determine which systems handle cardholder data and what connects to them
  4. Purchase a compliance management platform to track the requirements

Answer: C — Determine which systems handle cardholder data and what connects to them

C) Correct - scoping is the foundational activity: the standard's requirements apply to the cardholder data environment and connected systems, and scope errors invalidate everything built on top. A) Enterprise-wide encryption is disproportionate and does not establish where the obligations apply. B) Assessment before scoping wastes the engagement and produces unreliable findings. D) Tooling helps track work that scoping has yet to define.

An organisation is choosing a controls catalogue. Which BEST supports a US federal government context?

  1. ISO/IEC 27002:2022, the international guidance for information security controls
  2. The CIS Critical Security Controls, a prioritised operational baseline of safeguards
  3. NIST SP 800-53 Rev. 5, the federal catalogue of security and privacy controls
  4. PCI DSS 4.0.1, the payment brands' standard for cardholder data environments

Answer: C — NIST SP 800-53 Rev. 5, the federal catalogue of security and privacy controls

C is the fit: SP 800-53 Rev. 5 is the control catalogue mandated for US federal information systems and the basis for agency authorisation. A is an international guidance set used with ISO/IEC 27001, appropriate elsewhere but not the federal baseline. B is a prioritised operational baseline rather than an authorisation catalogue. D applies only to cardholder data environments. The skill tested is matching catalogue to regulatory context, not ranking catalogues by quality.

Which BEST describes a detective control?

  1. It blocks an unauthorized action at the point of entry before any harm reaches the target asset
  2. It restores affected systems and data to a known good state after an incident has been contained
  3. It identifies that an incident has occurred or is under way, as with SIEM alerting and audit logs
  4. It removes exposure by ending the business activity that gives rise to the risk in the first place
  5. It applies unpredictable checks so that no attacker can anticipate when review will be performed

Answer: C — It identifies that an incident has occurred or is under way, as with SIEM alerting and audit logs

C is the definition: detective controls do not stop an event but reveal it, through log review, alerting, monitoring and reconciliation, so that response can begin. A describes a preventive control such as a firewall rule or access restriction. B describes a corrective control such as restoration from backup. D describes risk avoidance, a treatment decision rather than a control function. E describes an attribute some controls have, not a control category.

Information Security Program — Development and Resources flashcards

2 cards from the 32 in this chapter.

Control categories (functional)?

Preventive, Detective, Corrective, Deterrent, Recovery, Compensating.

Which sequence should drive control selection, and what is the common inversion?

Business objective and obligation, then risk assessment, then required control objective, then control selection and design, then measurement. The common inversion is selecting a technology or framework control set first and retrofitting a justification, which produces controls that cannot be traced to any accepted risk.

Practise the full chapter

These are a sample. The full Information Security Program — Development and Resources chapter runs 98 items with per-chapter progress tracking, on the web and in the iOS app.

Open CISM in CoStudy →

Other CISM chapters

All CISM practice questions →