nerdexam
Isaca

CISM · Question #265

Which of the following provides the BEST evidence that a security program is mature?

The correct answer is C. Controls are implemented based on risk assessment results. A risk assessment-driven control selection process is the hallmark of a mature security program because it is proactive, systematic, and business-aligned. Mature programs identify and prioritize risks before controls are selected, ensuring resources are applied where they…

Submitted by diego_uy· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following provides the BEST evidence that a security program is mature?

Options

  • AControls are implemented based on vulnerability assessment results.
  • BControls are implemented based on root cause analysis of incidents.
  • CControls are implemented based on risk assessment results.
  • DControls are implemented based on security audit findings.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    14% (4)
  • C
    79% (23)
  • D
    3% (1)

Explanation

A risk assessment-driven control selection process is the hallmark of a mature security program because it is proactive, systematic, and business-aligned. Mature programs identify and prioritize risks before controls are selected, ensuring resources are applied where they reduce the most risk. Controls driven by vulnerability assessments (A) are technically reactive and narrow in scope. Controls driven by root cause analysis of incidents (B) are purely reactive - waiting for harm before acting. Controls driven by audit findings (D) are compliance-oriented and backward-looking. Only risk assessment-driven controls reflect the forward-looking, proportional, and strategic decision-making that characterizes program maturity.

Topics

#Security Program Maturity#Risk-Based Approach#Control Implementation#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice