CISM Exam Questions 2026 – Practice Test with Verified Answers

Home / ISACA / CISM

Latest CISM Exam Practice Questions

The practice questions for CISM exam was last updated on 2026-08-23 .

Viewing page 1 out of 27 pages.

Viewing questions 1 out of 137 questions.

Question#1

Recommendations for enterprise investment in security technology should be PRIMARILY based on:

A. adherence to international standards
B. availability of financial resources
C. the organization s risk tolerance
D. alignment with business needs

Explanation:
Verified Answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section
Explanation: 3.2.1.1, "Recommendations for enterprise investment in security technology should be primarily based on the organization’s risk tolerance."1
The organization’s risk tolerance is the degree of uncertainty that the organization is willing to accept in order to pursue its objectives. It reflects the organization’s appetite for risk and its ability to cope with potential losses or disruptions. The higher the risk tolerance, the more aggressive and innovative the security investments can be, as they can help achieve faster growth or competitive advantage. The lower the risk tolerance, the more conservative and defensive the security investments should be, as they can help protect the organization’s assets and reputation from potential threats.
Reference: 1: CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.1

Question#2

Which of the following BEST determines an information asset's classification?

A. Value of the information asset in the marketplace
B. Criticality to a business process
C. Risk assessment from the data owner
D. Cost of producing the information asset

Explanation:
According to the CISM Review Manual, 15th Edition1, information asset classification is the process of assigning a level of sensitivity to information assets based on their importance to the organization and the potential impact of unauthorized disclosure, modification or destruction. The criticality of an information asset to a business process is one of the key factors that determines its classification level.
Reference = 1: CISM Review Manual, 15th Edition, ISACA, 2016, Chapter 2, page 61.

Question#3

An organization is increasingly using Software as a Service (SaaS) to replace in-house hosting and support of IT applications.
Which of the following would be the MOST effective way to help ensure procurement decisions consider information security concerns?

A. Integrate information security risk assessments into the procurement process.
B. Provide regular information security training to the procurement team.
C. Invite IT members into regular procurement team meetings to influence best practice.
D. Enforce the right to audit in procurement contracts with SaaS vendors.

Explanation:
The best way to ensure that information security concerns are considered during the procurement of SaaS solutions is to integrate information security risk assessments into the procurement process. This will allow the organization to identify and evaluate the potential security risks and impacts of using a SaaS provider, and to select the most appropriate solution based on the risk appetite and tolerance of the organization. Information security risk assessments should be conducted at the early stages of the procurement process, before selecting a vendor or signing a contract, and should be updated periodically throughout the contract lifecycle.
Providing regular information security training to the procurement team (B) is a good practice, but it may not be sufficient to address the specific security issues and challenges of SaaS solutions. The procurement team may not have the expertise or the authority to conduct information security risk assessments or to negotiate security requirements with the vendors.
Inviting IT members into regular procurement team meetings to influence best practice © is also a good practice, but it may not be effective if the IT members are not involved in the actual procurement process or decision making. The IT members may not have the opportunity or the influence to conduct information security risk assessments or to ensure that security concerns are adequately addressed in the procurement contracts.
Enforcing the right to audit in procurement contracts with SaaS vendors (D) is an important control, but it is not the most effective way to ensure that information security concerns are considered during the procurement process. The right to audit is a post-contractual measure that allows the organization to verify the security controls and compliance of the SaaS provider, but it does not prevent or mitigate the security risks that may arise from using a SaaS solution. The right to audit should be complemented by information security risk assessments and other security requirements in the procurement contracts.
Reference = CISM Review Manual (Digital Version), Chapter 3: Information Security Program
Development and Management, Section: Information Security Program Management, Subsection:
Procurement and Vendor Management, Page 141-1421

Question#4

Which of the following BEST facilitates an information security manager's efforts to obtain senior management commitment for an information security program?

A. Presenting evidence of inherent risk
B. Reporting the security maturity level
C. Presenting compliance requirements
D. Communicating the residual risk

Explanation:
Communicating the residual risk is the best way to facilitate an information security manager’s efforts to obtain senior management commitment for an information security program. The residual risk is the level of risk that remains after applying the security controls and mitigation measures. The residual risk reflects the effectiveness and efficiency of the information security program, as well as the potential impact and exposure of the organization. The information security manager should communicate the residual risk to the senior management in a clear, concise, and relevant manner, using quantitative or qualitative methods, such as risk matrices, heat maps, dashboards, or reports.
The communication of the residual risk should also include the comparison with the inherent risk, which is the level of risk before applying any security controls, and the risk appetite, which is the level of risk that the organization is willing to accept. The communication of the residual risk should help the senior management to understand the value and performance of the information security program, as well as the need and justification for further investment or improvement. Presenting evidence of inherent risk, reporting the security maturity level, and presenting compliance requirements are all important aspects of the information security program, but they are not the best ways to obtain senior management commitment. These aspects may not directly demonstrate the benefits or outcomes of the information security program, or they may not align with the business objectives or priorities of the organization .
For example, presenting evidence of inherent risk may show the potential threats and vulnerabilities that the organization faces, but it may not indicate how the information security program addresses or reduces them. Reporting the security maturity level may show the progress and status of the information security program, but it may not relate to the risk level or the business impact. Presenting compliance requirements may show the legal or regulatory obligations that the organization must fulfill, but it may not reflect the actual security needs or goals of the organization. Therefore, communicating the residual risk is the best way to obtain senior management commitment for an information security program, as it shows the results and value of the information security program for the organization.
Reference = CISM Review Manual 2023, page 41 1; CISM Practice Quiz 2

Question#5

Which of the following should review and approve the objectives within an organization’s information security framework?

A. Information security steering committee
B. Chief information security officer
C. Chief information officer
D. Information security manager

Explanation:
The correct answer is A because an information security steering committee provides cross-functional governance oversight and helps ensure that information security objectives align with enterprise goals. Security framework objectives affect multiple business areas, including risk management, compliance, operations, technology, legal, and executive management. Therefore, approval should not rest solely with the information security manager, CISO, or CIO. The CISO and information security manager may develop and recommend objectives, while the CIO may provide technology leadership, but the steering committee is better positioned to review, prioritize, and approve objectives from an enterprise governance perspective. In CISM, effective information security governance requires senior-level direction, oversight, and alignment with business objectives. A steering committee also helps resolve conflicts, allocate resources, and ensure accountability across the organization. Because the framework establishes the direction and expectations for the security program, approval by the steering committee provides broader business representation and governance authority.
Reference: CISM Information Security Governance; steering committee, governance structure, security framework, and strategic alignment principles.

Disclaimer

This page is for educational and exam preparation reference only. It is not affiliated with ISACA, CISM Certification, or the official exam provider. Candidates should refer to official documentation and training for authoritative information.

Exam Code: CISMQ & A:  1044  Q&As Updated:  2026-08-23

  Get All CISM Q&As