CISM - Information Security Risk Management - Section 2.2

Conduct vulnerability and control deficiency analysis to identify gaps in the security posture.

Conduct vulnerability assessments and gap analysis to identify control deficiencies and weaknesses in the organisation's security posture. Use findings from penetration testing alongside gap analysis results to prioritise remediation and strengthen the overall control environment.

Vulnerability assessmentControl gapsGap analysisPenetration testing

Practice question for this objective

Free sampleInformation Security Risk Managementhard

An information security manager is planning the annual posture assessment and must decide how to sequence a control gap analysis and a technical vulnerability assessment for a newly acquired business unit whose control environment is largely undocumented. Which sequencing is most defensible from a management standpoint?

  • APerform the gap analysis first to establish which controls should exist, then use the vulnerability assessment to test how well those controls hold up technically. Correct
  • BRun only the vulnerability assessment, because exploitable technical flaws are the sole reliable evidence of where the security posture is genuinely weak.
  • CRun both in parallel without reference to each other, then merge the two reports at the end so neither activity delays the other.
  • DDefer both assessments until the business unit has documented its own controls, so that the analysis can rely entirely on the unit's existing records.
Establish the required control baseline through gap analysis first, then run the vulnerability assessment to test how those controls perform technically. A gap analysis defines which controls should exist and creates the reference frame. Running it before the technical assessment lets vulnerability findings be interpreted against required controls, producing a coherent posture view rather than disconnected technical results.

Why A is correct: Correct because establishing the required control baseline first gives the technical assessment a frame of reference, so deficiencies can be interpreted against what should be in place.

Why B is wrong: Tempting because technical findings are concrete, but a scan alone cannot reveal missing or undesigned controls, so it leaves governance and process gaps invisible.

Why C is wrong: Tempting because parallel work is faster, but without a control baseline the technical findings cannot be interpreted against required controls, so the merge yields a fragmented posture view.

Why D is wrong: Tempting because documentation aids analysis, but waiting on an undocumented unit leaves the acquirer blind to active risk, so deferral abdicates the manager's duty to assess posture.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.