Certified Information Security Manager (CISM)Information Security ProgramEasy

A CISO is tasked with implementing a new information security program. To ensure the program's activities are systematically reviewed, evaluated, and improved over time, which of the following processes should be formally integrated into the program management lifecycle?

  1. AAnnual budget reallocation based on current market trends.
  2. BOne-time external security audit upon program completion.
  3. CContinuous monitoring and periodic program reviews.
  4. DAd-hoc penetration testing whenever a new system is deployed.
Show answer & explanation

Correct answer: C. Continuous monitoring and periodic program reviews.

Continuous monitoring and periodic program reviews are essential for ensuring an information security program remains effective, adapts to changing threats, and continually improves. This systematic approach allows for ongoing evaluation and adjustment, which is key to long-term success.

Why the other options are wrong

  • A. Budget reallocation is a financial process, not a direct mechanism for program review and improvement.
  • B. A one-time audit provides a snapshot but doesn't ensure continuous improvement or adaptation.
  • D. Ad-hoc penetration testing is a valuable security activity but doesn't constitute a formal process for overall program evaluation and improvement.

Continuous Security Improvement

An ongoing process of regularly assessing, evaluating, and enhancing an information security program to adapt to evolving threats, technologies, and organizational needs.

  • Ensures long-term program effectiveness.
  • Involves monitoring and periodic reviews.
  • Essential for adapting to change.

Memory trick: Continual Checks Create Constant Control.

More Information Security Program questions