Information Security Program
50 practice questions with explanations — 15 free to try
PassNova has 50 CISM practice questions on Information Security Program, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Information Security Program: example questions & answers
3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 50-question Information Security Program bank is part of PassNova Premium.
An information security program's objectives should be derived PRIMARILY from which of the following?
- AThe most recent security conference recommendations
- BThe latest security product features available on the market
- CThe information security strategy and business requirements✓
- DThe preferences of the network administration team
Answer: Program objectives flow from the security strategy and business requirements so the program delivers outcomes the organisation actually needs.
What is the MOST important success factor when implementing a security awareness training program?
- ATesting employees once at the time of hiring and never again afterwards
- BUsing the most expensive e-learning platform available
- CTailoring the content to the audience and reinforcing it regularly✓
- DDelivering all of the training material in a single annual classroom session
Answer: Awareness is most effective when content is tailored to the audience and reinforced regularly, sustaining behaviour change rather than a one-off event.
When selecting security controls for the information security program, what should be the PRIMARY consideration?
- AThe number of controls that can be deployed within the current quarter
- BThe set of controls used by the organisation's largest competitor
- CThe level of risk the controls are intended to reduce✓
- DThe vendor offering the largest discount on a multi-year licence
Answer: Controls should be selected based on the risk they reduce, ensuring effort and spend are aligned to the organisation's actual exposure.