CISM - Information Security Risk Management (20% of the exam) - Section 2.2

Conduct vulnerability and control deficiency analysis to identify gaps in the security posture.

Conduct vulnerability assessments and gap analysis to identify control deficiencies and weaknesses in the organisation's security posture. Use findings from penetration testing alongside gap analysis results to prioritise remediation and strengthen the overall control environment.

Vulnerability assessmentControl gapsGap analysisPenetration testing

Practice question for this objective

Free sampleInformation Security Risk Managementhard

An information security manager is planning the annual posture assessment and must decide how to sequence a control gap analysis and a technical vulnerability assessment for a newly acquired business unit whose control environment is largely undocumented. Which sequencing is most defensible from a management standpoint?

  • APerform the gap analysis first to establish which controls should exist, then use the vulnerability assessment to test how well those controls hold up technically. Correct
  • BRun only the vulnerability assessment, because exploitable technical flaws are the sole reliable evidence of where the security posture is genuinely weak.
  • CRun both in parallel without reference to each other, then merge the two reports at the end so neither activity delays the other.
  • DDefer both assessments until the business unit has documented its own controls, so that the analysis can rely entirely on the unit's existing records.
Establish the required control baseline through gap analysis first, then run the vulnerability assessment to test how those controls perform technically. A gap analysis defines which controls should exist and creates the reference frame. Running it before the technical assessment lets vulnerability findings be interpreted against required controls, producing a coherent posture view rather than disconnected technical results.

Why A is correct: Correct because establishing the required control baseline first gives the technical assessment a frame of reference, so deficiencies can be interpreted against what should be in place.

Why B is wrong: Tempting because technical findings are concrete, but a scan alone cannot reveal missing or undesigned controls, so it leaves governance and process gaps invisible.

Why C is wrong: Tempting because parallel work is faster, but without a control baseline the technical findings cannot be interpreted against required controls, so the merge yields a fragmented posture view.

Why D is wrong: Tempting because documentation aids analysis, but waiting on an undocumented unit leaves the acquirer blind to active risk, so deferral abdicates the manager's duty to assess posture.

See more CISM practice questions, answers explained.

Exam traps in Information Security Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • A vulnerability, because the absence of recent reviews is a technical weakness that an attacker could exploit to retain unauthorised access.

    Why it is wrong: Labelling it a vulnerability is tempting because dormant access can be abused, but a vulnerability is an inherent weakness in an asset, whereas the issue here is that a defined control exists yet is not being operated.

  • The vulnerability scan is a governance activity owned by the board, whereas the gap analysis is a purely technical task delegated to the operations team.

    Why it is wrong: Tempting because the two do sit at different levels, but it misassigns ownership: scanning is technical and gap analysis is the governance-aligned comparison, so the roles are reversed.

  • Penetration testing enumerates a broader set of known weaknesses across all hosts, giving wider coverage than a vulnerability scan can achieve.

    Why it is wrong: This inverts the relationship: breadth of coverage across many hosts is the strength of automated scanning, not penetration testing, so it does not explain why a test better demonstrates achievable business impact.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.