CISM - Information Security Program (33% of the exam) - Section 3.8

Test and evaluate information security controls to verify that they operate as intended.

Test and evaluate information security controls through audits, control testing, and penetration testing to verify that each control operates as intended. Interpret effectiveness evaluation results to identify controls that are designed correctly but fail operationally, and distinguish these from controls that require redesign.

Control testingAuditPenetration testingEffectiveness evaluation

Practice question for this objective

Free sampleInformation Security Programmedium

An organisation engages a third party for a black-box penetration test of its internet-facing applications. The test report lists several exploitable vulnerabilities. From an information security management perspective, what is the most important reason to also perform internal control testing rather than relying on the penetration test alone to evaluate the control environment?

  • AA penetration test is performed by an external party, so its findings cannot be used as audit evidence without internal corroboration.
  • BA penetration test only covers the network layer, so application and data-layer controls are always outside its scope.
  • CA penetration test produces false positives that must be re-validated, which internal control testing is designed to eliminate.
  • DA penetration test confirms exploitability of weaknesses found but does not evaluate whether preventive and detective controls across the environment are operating as intended. Correct
Understand that penetration testing proves exploitability of specific paths but does not substitute for systematic evaluation of whether all controls operate as intended. A penetration test is a point-in-time, attacker-perspective probe of selected paths. It can confirm that weaknesses are exploitable but does not assess every preventive and detective control or confirm they operate as designed, which is why a control-testing programme is required to evaluate the overall control environment.

Why A is wrong: This is tempting because independence and evidence handling matter, but external test results are routinely valid evidence; the real limitation is scope, not the tester's external status, so this misstates the reason.

Why B is wrong: This sounds plausible, but the scenario describes an application penetration test, and penetration tests can target application and data layers; the blanket claim about scope is factually wrong.

Why C is wrong: Re-validating findings is a real activity, but eliminating false positives is not the purpose of internal control testing, and a clean penetration test would still leave the wider control environment unevaluated, so this misidentifies the main reason.

Why D is correct: Penetration testing demonstrates whether specific attack paths can be exploited at a point in time; it is not a systematic evaluation of whether each designed control operates as intended, so broader control testing is needed to evaluate the control environment.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Draw a large statistical sample of transactions across the period and inspect each for evidence that encryption was applied.

    Why it is wrong: Large statistical sampling is appropriate for controls with human variability, but for a deterministic automated control that behaves identically each time, a large sample wastes effort and is tempting only by analogy to manual-control testing.

  • Confirm that the DLP licence count matches the asset register so that every endpoint is covered by the deployment.

    Why it is wrong: Licence-to-asset reconciliation tests deployment coverage, which is design and presence, but it still says nothing about whether the control actually blocks or alerts on real data egress, so it does not establish operating effectiveness.

  • Having the operations team retest its own controls more frequently, since the team understands the controls best and can spot subtle failures fastest.

    Why it is wrong: It is tempting because the team knows the control intimately, but self-testing the control you operate creates a self-review threat that undermines credible assurance.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.