Home › Certifications › CISM › Information Security Program — Development and Resources
66 multiple-choice questions and 32 flashcards on Information Security Program — Development and Resources, about 17% of the CISM bank. Every one carries a written rationale.
Information Security Program — Development and Resources is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 66 of the bank's 400 multiple-choice questions — roughly 17% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Which factor is MOST important when deciding whether to outsource a security capability?
Answer: C — Whether it requires deep enterprise context to perform well
C) Correct - capabilities that depend on intimate knowledge of the business, its systems and its people degrade when moved outside, while commoditised, context-light capabilities transfer well. A) Cost comparison matters but choosing on price alone routinely outsources the wrong things. B) Market availability describes what is possible, not what is wise. D) Accommodation is a logistical consideration well below the sourcing decision.
A maturity assessment is MOST useful when:
Answer: D — Used to find gaps against a risk-appetite target and fund a roadmap
D is the key: maturity has value only when it drives prioritized investment against a risk-based target. A misses business context. B has no external reference. C loses the detail needed to decide anything.
A newly hired security manager is asked to build an information security programme from scratch. The FIRST activity should be to:
Answer: B — understand the business objectives, obligations and risk appetite
B) Correct - a programme is an instrument for delivering business outcomes, so its objectives must be derived from what the enterprise is trying to achieve and what it is obliged to do. A) Framework selection before understanding requirements produces a checklist programme that is expensive and poorly aligned. C) Hiring precedes knowing what capabilities are needed and locks in the wrong skill mix. D) Deploying controls first is activity without direction and creates commitments that are hard to unwind.
A compensating control is appropriate when:
Answer: D — The primary control is infeasible and the alternative is equivalent
D is the key: a compensating control is a deliberate substitute that must demonstrate equivalent risk reduction and be approved. A removes the reason to compensate. B is vendor-led control selection. C confuses assurance scheduling with control design.
The PRIMARY objective of an information security programme is to:
Answer: B — Deliver capabilities that achieve the strategy and protect value within appetite
B ties the programme to outcomes: it exists to build and sustain the capabilities that deliver the security strategy and protect business value within the risk appetite that leadership has set. A treats a guidance catalogue as a target, ignoring that controls are selected by risk. C sets an absolute technical metric that consumes resource with no reference to criticality. D makes assurance the objective, so the programme optimises for evidence rather than exposure.
Cryptography governance is BEST exercised through:
Answer: B — Enterprise standards for algorithms, key length, lifecycle and key ownership
B is governance in the proper sense: an approved standard fixes acceptable algorithms and key lengths, defines the key lifecycle and names the roles accountable for it, which gives the organisation one place to change when guidance moves, as it is doing with the migration to post-quantum standards. A produces drift toward whatever each team finds convenient. C outsources execution but not accountability for the keys. D discards a capability that key exchange and digital signature depend on.
An enterprise reports mean time to remediate vulnerabilities as a single enterprise-wide average. The MOST useful improvement would be to:
Answer: D — segment the measure by asset criticality and severity
D) Correct - a single average lets fast fixes on trivial systems mask slow remediation on critical ones, so segmentation is what makes the number decision-relevant. A) The median handles outliers but still conflates critical and trivial assets. B) More frequent reporting of an uninformative aggregate simply produces it more often. C) Adding volume alongside duration compounds activity counting rather than clarifying exposure.
An enterprise processes card payments and must design controls accordingly. Which is the MOST appropriate first step in applying the payment card standard?
Answer: C — Determine which systems handle cardholder data and what connects to them
C) Correct - scoping is the foundational activity: the standard's requirements apply to the cardholder data environment and connected systems, and scope errors invalidate everything built on top. A) Enterprise-wide encryption is disproportionate and does not establish where the obligations apply. B) Assessment before scoping wastes the engagement and produces unreliable findings. D) Tooling helps track work that scoping has yet to define.
An organisation is choosing a controls catalogue. Which BEST supports a US federal government context?
Answer: C — NIST SP 800-53 Rev. 5, the federal catalogue of security and privacy controls
C is the fit: SP 800-53 Rev. 5 is the control catalogue mandated for US federal information systems and the basis for agency authorisation. A is an international guidance set used with ISO/IEC 27001, appropriate elsewhere but not the federal baseline. B is a prioritised operational baseline rather than an authorisation catalogue. D applies only to cardholder data environments. The skill tested is matching catalogue to regulatory context, not ranking catalogues by quality.
Which BEST describes a detective control?
Answer: C — It identifies that an incident has occurred or is under way, as with SIEM alerting and audit logs
C is the definition: detective controls do not stop an event but reveal it, through log review, alerting, monitoring and reconciliation, so that response can begin. A describes a preventive control such as a firewall rule or access restriction. B describes a corrective control such as restoration from backup. D describes risk avoidance, a treatment decision rather than a control function. E describes an attribute some controls have, not a control category.
2 cards from the 32 in this chapter.
Control categories (functional)?
Preventive, Detective, Corrective, Deterrent, Recovery, Compensating.
Which sequence should drive control selection, and what is the common inversion?
Business objective and obligation, then risk assessment, then required control objective, then control selection and design, then measurement. The common inversion is selecting a technology or framework control set first and retrofitting a justification, which produces controls that cannot be traced to any accepted risk.
These are a sample. The full Information Security Program — Development and Resources chapter runs 98 items with per-chapter progress tracking, on the web and in the iOS app.