Home › Certifications › CISM › Information Security Program — Operations, Architecture and Third Party
66 multiple-choice questions and 31 flashcards on Information Security Program — Operations, Architecture and Third Party, about 17% of the CISM bank. Every one carries a written rationale.
Information Security Program — Operations, Architecture and Third Party is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 66 of the bank's 400 multiple-choice questions — roughly 17% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
A strategic partner's integration cannot use the enterprise's standard authorisation model, and the delivery date is fixed. The BEST course of action is to:
Answer: B — Have the risk owner decide, informed by the exposure and the compensating controls now available
B) Correct — deviations from standard are risk decisions belonging to the accountable owner, and the manager's job is to present exposure and options clearly enough for that decision to be informed. A) A flat block substitutes the security function's judgement for the business owner's. C) Approving on revenue grounds alone skips the analysis that makes the acceptance defensible. D) Engineering around a review to hide a deviation is a governance failure regardless of the technical merits.
Immediately after an acquisition, the business wants the acquired company's network connected to the parent's so integration can begin. The BEST approach is to:
Answer: D — Permit only the connectivity that specific integration needs require, assessed and time-bound
D) Correct — risk-proportionate, purpose-specific and time-limited connectivity lets integration proceed while the unknown estate is assessed, which balances business urgency against inherited exposure. A) Connecting first and assessing later exposes the parent to whatever the acquired environment already contains. B) A full baseline before any connectivity is rarely achievable and makes security the blocker to the deal's value. C) Letting the acquired party define the rule set delegates the risk decision to the party whose posture is unverified.
Emergency changes routinely bypass the change advisory board. The BEST control design is to:
Answer: C — Permit them under defined criteria, with mandatory retrospective review and approval
C) Correct — emergency change is legitimate and necessary, so governance defines when it may be invoked and guarantees after-the-fact scrutiny, which preserves both speed and accountability. A) Prohibition in regulated scope guarantees that outages there cannot be fixed quickly. B) Routing every urgent fix through one individual creates a single point of delay and failure. D) Labelling all emergency changes as incidents wastes investigative capacity and discourages legitimate use of the path.
Which BEST reflects good practice in managing outsourcing and third-party risk?
Answer: B — Risk-based due diligence, security terms with audit and breach notification, and ongoing monitoring
B describes a life cycle rather than an event: assess the provider in proportion to the risk it carries, embed security requirements, audit rights, breach notification and service levels in the contract, then monitor throughout the relationship and coordinate incident response across the boundary. A relies on paper alone. C substitutes reputation for evidence. D is an avoidance posture that is rarely viable commercially. E is the most common real failure, since provider risk changes long before the contract does.
For governance purposes, the security architecture documentation should PRIMARILY record:
Answer: B — The control objectives, where each is placed, and who owns and provides assurance over it
B) Correct — architecture at management level is a statement of control objectives, placement, ownership and assurance, which is what makes it governable and auditable over time. A) Product and configuration standards implement the architecture but change frequently and describe means, not intent. C) Topology diagrams are essential engineering artifacts yet do not express who is accountable for which control. D) A delivery roadmap is a plan, not an architecture, and it will not survive contact with changing priorities.
Under a shared responsibility model for infrastructure as a service, accountability for protecting enterprise data placed in the service:
Answer: A — Remains with the enterprise, irrespective of the controls the provider operates
A) Correct — operation of specific controls can be shared, but accountability for the enterprise's data and for its regulatory obligations is never outsourced. B) An assurance report evidences that the provider operates certain controls; it does not move accountability. C) Commercial tiers change service levels and support, not who answers for the data. D) The split of operated controls varies by service model and is not a clean storage-versus-network division.
Data flow mapping reveals that regulated data is decrypted at an integration broker sitting outside the regulated zone. The security manager's NEXT step should be to:
Answer: D — Assess the exposure and present treatment options to the accountable data owner
D) Correct — a newly identified gap is first analysed and then put to the owner with options; selecting the treatment before the exposure is understood is the recurring management error. A) Re-platforming may well be the right treatment, but mandating it pre-empts the owner's decision and the cost comparison. B) Monitoring plus an exception entry documents the gap without treating it or informing the decision-maker. C) End-to-end encryption is one candidate treatment and may be incompatible with what the broker must do to the data.
A reporting framework produces security reports for the board, for business unit heads and for IT operations. What should MOST vary between them?
Answer: B — The level of aggregation and the specific decision each audience is being asked to make
B) Correct — audience-appropriate reporting draws on one consistent data set but changes granularity and framing to match the decision rights of each audience. A) Recalculating data per audience destroys consistency and invites contradictory numbers in the same enterprise. C) Frequency may differ for practical reasons, but deliberately desynchronising it to prevent comparison is the wrong objective. D) Appetite is set once at enterprise level; cascading it into limits is possible, but restating the appetite itself per audience undermines its authority.
A review of non-human accounts used by applications and automation identifies a governance weakness. The MOST significant is that these identities:
Answer: C — Often lack a named owner and any defined lifecycle for review, rotation and revocation
C) Correct — ownerless machine identities accumulate entitlements, outlive their purpose and are never recertified, which is the governance failure that turns them into standing attack paths. A) Exclusion from password standards is a symptom of the missing lifecycle rather than the underlying problem. B) Workload authentication uses certificates, keys and platform-issued credentials, so the absence of multifactor is not the defining issue. D) Who creates them matters less than whether anyone is accountable for reviewing them afterwards.
A critical supplier declines an on-site audit, offering instead a recent independent assurance report on its service. The BEST response is to:
Answer: C — Review the report's scope, period covered and noted exceptions against the services actually consumed
C) Correct — an assurance report can satisfy the need, but only after management checks that the scope covers the service used, the period is current and the exceptions do not touch relied-upon controls. A) A well-scoped report over an operating period does evidence control operation; insisting on an audit ignores a valid alternative. B) Accepting without reading the scope and exceptions is the classic false comfort in third-party assurance. D) A self-completed questionnaire is weaker evidence than an independent opinion, so substituting it is a step backwards.
4 cards from the 31 in this chapter.
AAA?
Authentication, Authorization, Accounting (audit logs).
IaaS/PaaS/SaaS responsibilities?
IaaS: most customer responsibility. PaaS: shared. SaaS: most provider.
Why is an availability SLA an insufficient measure of a provider's security performance?
Availability says nothing about confidentiality or integrity, about patching and vulnerability remediation timelines, incident notification speed, or control effectiveness. Security service levels must specify measurable, evidenced security obligations with remedies, or the SLA only guarantees the service is up while insecure.
A major cloud provider will not grant a right-to-audit clause. What is the acceptable alternative and what must the manager still do?
Accept independent third-party assurance — an in-scope certification such as ISO/IEC 27001:2022 or a service auditor's report — as substitute evidence. The manager must still review the scope, the period covered, exclusions and any exceptions noted, and map the provider's controls to the enterprise's own control requirements, documenting any gaps as residual risk for the risk owner.
These are a sample. The full Information Security Program — Operations, Architecture and Third Party chapter runs 97 items with per-chapter progress tracking, on the web and in the iOS app.