CISM Information Security Governance: 131 practice questions
12 of the 131 Information Security Governance questions in the Certsqill CISM bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISM? Take the free 5-min readiness check →
1. Develop a security strategy that explicitly maps security: What should the CISM do FIRST to address this situa
- Develop a security strategy that explicitly maps security objectives to business goals and present that alignment to executive leadership for endorsement. ✓Correct. The CISM's primary responsibility is ensuring the information security program is aligned with the organization's business strategy and objectives. Developing a strategy that links security objectives to business goals demonstrates value, reduces friction, and gains executive support.
- Expand security awareness training for business unit managers so they better understand why existing security controls sometimes delay revenue-generating initiatives.Incorrect. Awareness training addresses knowledge gaps among staff, but does not resolve the strategic misalignment between the security program and business objectives. The problem is governance-level, not training-level.
- Conduct a gap analysis comparing current security controls against applicable regulatory requirements and report the resulting deficiencies to leadership.Incorrect. While regulatory compliance is important, performing a gap analysis does not address the core problem of misalignment between security and business strategy. This action would further reinforce the perception of security as a compliance function rather than a business enabler.
- Establish a risk acceptance process that lets business units bypass certain security controls on revenue-generating projects when justified.Incorrect. Simply creating workarounds without strategic alignment does not resolve the underlying governance issue and could introduce significant unmanaged risk. Risk acceptance should follow a formal process tied to risk appetite, not be used as a default bypass mechanism.
The CISM must first align the security strategy with business objectives to demonstrate that security is a business enabler, not an obstacle.
2. COBIT for IT governance and enterprise alignment: Which combination BEST satisfies both requirements?
- COBIT for IT governance; NIST SP 800-53 for information security controls.Incorrect. NIST SP 800-53 is a controls catalog primarily designed for US federal agencies. While it is comprehensive, it is not the international standard for information security management systems. ISO 27001 is more appropriate for an international manufacturing company seeking a globally recognized security management framework.
- COBIT for IT governance and enterprise alignment; ISO 27001 for information security controls. ✓Correct. COBIT (Control Objectives for Information and Related Technologies) is designed to bridge IT governance with enterprise governance and provides a comprehensive metrics framework for IT performance. ISO 27001 provides a systematic approach to managing information security with a defined set of controls (Annex A). Using both together satisfies the CIO's governance and metrics requirements and the CISO's security controls requirements.
- ISO 27001 for both IT governance and information security controls, since it covers both domains.Incorrect. ISO 27001 is an information security management system (ISMS) standard and does not specifically address enterprise IT governance integration and IT performance metrics in the way COBIT does. Using ISO 27001 alone would not fully satisfy the CIO's requirement for enterprise-level IT governance.
- NIST CSF for IT governance; ISO 27001 for information security controls.Incorrect. While the NIST Cybersecurity Framework (CSF) provides a risk-based approach to security, it is not specifically designed to integrate IT governance with enterprise governance in the way COBIT does. COBIT is the more appropriate choice for meeting enterprise governance alignment and IT performance measurement requirements.
COBIT addresses IT governance and enterprise alignment with performance metrics; ISO 27001 provides the information security management system and controls framework.
3. Establish a policy hierarchy where business unit: What is the MOST appropriate approach to resolve this situat
- Update the enterprise policy to adopt the most restrictive requirements found across all business units so every unit follows one consistent, stringent, enterprise-wide standard.Incorrect. Updating the enterprise policy to match the most restrictive local requirements may impose unnecessary burdens on business units that do not have those risk levels. Enterprise policies should reflect the organization's overall risk appetite, not the most restrictive subset of requirements.
- Allow each business unit to keep its own procedures provided it documents a business justification, without requiring any formal enterprise exception process.Incorrect. Allowing procedures that are less restrictive than the enterprise policy without a formal exception process creates inconsistent security posture and undermines the governance framework. Business justification alone is insufficient without formal risk assessment and approval.
- Establish a policy hierarchy where business unit procedures must meet or exceed enterprise policy standards, with any exceptions requiring formal risk acceptance. ✓Correct. A well-governed information security program uses a policy hierarchy: enterprise policy sets minimum standards, standards define specific requirements, procedures provide operational detail, and guidelines offer recommendations. Business unit procedures should always meet or exceed enterprise policy minimum standards. Where business context requires lower standards, a formal exception process with risk acceptance is required. More restrictive local procedures are acceptable as long as they align with the enterprise framework.
- Require all business units to withdraw their local procedures and rely solely on the enterprise policy for every operational security requirement going forward.Incorrect. Local procedures provide important operational specificity that enterprise policies cannot address for every business unit's unique context. Removing all local procedures would leave gaps in operational guidance and make the enterprise policy too generic to be practically implemented.
A policy hierarchy allows local procedures to exceed enterprise minimums but requires formal exception processes for procedures that fall below enterprise standards.
4. The business unit executive who holds accountability: Who should be assigned as the data owner?
- The CISM, because information security is ultimately responsible for protecting all of the organization's sensitive data assets and customer records enterprise-wide.Incorrect. The CISM is responsible for establishing the framework for data ownership and governance, but should not be the data owner for specific datasets. Concentrating ownership in the security function removes business accountability and creates a conflict of interest between protecting data and enabling business use.
- The IT department, because they build, operate, and secure the technical systems that physically store and process the sensitive customer data.Incorrect. IT departments are typically data custodians, responsible for the technical management and protection of data on behalf of the data owner. The data owner role requires business accountability for the data and its use, which is a business function responsibility, not a technical one.
- The Sales department, because they are the primary daily users of the data and best understand its commercial value and everyday business context.Incorrect. While Sales uses the data most frequently, being a primary user does not equate to data ownership. Data ownership should be assigned to the executive or senior manager of the business unit that has primary business responsibility and accountability for the data, which may not be the heaviest user.
- The business unit executive who holds accountability for the business process that creates, uses, and depends on the customer records held in the CRM. ✓Correct. Data ownership should be assigned to the business executive who has accountability for the business process that creates, uses, and depends on the data. This person has the authority to make business decisions about data classification, acceptable use, and access approvals. For customer records, this is typically the executive accountable for the customer relationship management business process.
Data ownership belongs to the business executive accountable for the business process, not IT custodians or primary users.
5. Training completion and phishing metrics measure: What is the MOST likely explanation and appropriate next ste
- Training completion and phishing metrics measure compliance and recognition, not behavioral change, so the CISM should implement behavioral metrics tied to actual job performance and introduce consequence management for repeated security violations. ✓Correct. This scenario illustrates the difference between security compliance (completing training, recognizing simulated phishing) and security culture (consistently making secure decisions in real contexts). High training completion and improved phishing scores measure knowledge and recognition, not actual behavior change. The increase in behavioral incidents indicates that employees know the rules but are not following them in practice—a culture problem, not a knowledge problem. The solution requires moving from compliance-based metrics to behavioral metrics embedded in job performance, combined with consequence management to reinforce accountable behavior.
- The phishing simulations have become too predictable, so employees learn only the specific simulated patterns rather than genuine awareness; the CISM should raise simulation difficulty, vary the lures, and increase their frequency across the entire employee population.Incorrect. While improving simulation realism is a valid tactical improvement, it addresses only one symptom. The scenario indicates a broader gap between measured training metrics and actual secure behavior across multiple incident types. Focusing solely on phishing simulation improvement would not address the systemic cultural issue.
- Security awareness training is fundamentally ineffective as a control, so the organization should retire it and instead require every employee to obtain a mandatory role-appropriate security certification to prove competence and reduce incidents.Incorrect. Security awareness training, when properly designed, is an effective control. The problem is not with training as a concept but with how success is being measured and how training connects to behavior. Replacing training with certifications would increase compliance pressure without addressing the behavioral culture gap.
- The rise in incidents reflects an expanding external threat landscape rather than employee behavior, so the CISM should invest in additional technical controls that reduce the organization's dependence on individual human judgment.Incorrect. The scenario specifically states that the incidents are 'caused by employee behavior,' ruling out the expanding threat landscape as the primary explanation. Additionally, reducing dependence on human judgment through technical controls is a valid defense-in-depth strategy but does not address the cultural problem that will continue to manifest in other ways.
High training completion and phishing scores measure compliance, not culture. Behavioral incidents reveal a gap between knowledge and action that requires behavioral metrics and consequence management.
6. Conduct comprehensive security due diligence immediately: What is the CISM's MOST critical recommendation to t
- Conduct comprehensive security due diligence immediately, covering technical security posture, GDPR compliance status, data processing agreements, and incident history, and ensure the findings directly inform the final purchase price and integration plan. ✓Correct. The CISM's most critical recommendation at this stage is to immediately conduct comprehensive security due diligence that covers: (1) Technical security posture (vulnerability state, security controls maturity), (2) GDPR compliance status (DPO appointment, DPIA completion, data subject rights processes, legal basis for processing), (3) Data processing agreements with the target's vendors and sub-processors, (4) Incident and breach history including unreported incidents, (5) Regulatory investigation or enforcement history. This due diligence should directly inform the purchase price (security liabilities can be negotiated as price adjustments) and the integration security roadmap. Missing this window means inheriting unknown security and compliance liabilities without contract protections.
- Recommend delaying the acquisition entirely until a full independent security audit can be completed, arguing that the compressed 90-day timeline is simply insufficient to perform any proper or defensible security due diligence.Incorrect. Recommending delay without first understanding what can be accomplished in 90 days is premature. Security due diligence can often be scoped to provide meaningful risk information within accelerated timelines. A blanket delay recommendation without a proposed alternative approach is not actionable and will likely be ignored by the executive team.
- Request that the target company hand over its most recent SOC 2 Type II report and its ISO 27001 certificate, and treat those third-party attestations as sufficient evidence that the target's security posture is adequate.Incorrect. While third-party certifications and audit reports are useful inputs, they are not sufficient for M&A due diligence. SOC 2 reports audit specific trust service criteria during a specific period and do not cover GDPR compliance or incident history. Relying on existing certifications without independent assessment would fail to identify current vulnerabilities and compliance gaps.
- Immediately commission a technical security assessment of the target company's production systems to identify exploitable vulnerabilities before the transaction closes, treating the technical posture as the single decisive factor in the overall acquisition decision.Incorrect. While technical security assessment is important, it addresses only one dimension of the risk. The scenario describes a GDPR-processing company, making regulatory compliance risk equally or more critical than technical vulnerabilities. A technical assessment without legal and compliance review would provide an incomplete risk picture.
M&A security due diligence must cover technical security, GDPR compliance status, incident history, and data processing agreements, with findings informing purchase price negotiations.
7. Maintain the current CIO reporting structure but add: Which reporting structure BEST addresses the board's con
- Maintain the current CIO reporting structure but add a dotted-line reporting relationship from the CISM to the board's audit committee. ✓Correct. A dual reporting structure—solid line to the CIO for operational coordination, dotted line directly to the board's audit committee for governance and escalation—addresses the conflict of interest concern while maintaining operational integration with IT. This structure allows the CISM to escalate material security concerns directly to the board without being filtered through the CIO, while preserving the operational coordination necessary for effective security program execution. This is consistent with ISACA's recommended governance model for organizations where full separation of CISM and CIO reporting is not operationally feasible.
- Create an independent Security department with the CISM reporting directly to the CEO, eliminating all potential reporting conflicts.Incorrect. While CEO reporting eliminates the CIO conflict of interest, it may not be appropriate for all organizations depending on size, industry, and security program maturity. More importantly, CEO reporting does not specifically address the board's concern about board-level escalation—the CEO can still filter information before it reaches the board.
- Move the CISM reporting line to the Chief Financial Officer, as the CFO provides executive-level oversight without IT conflict of interest.Incorrect. Reporting to the CFO reduces the conflict of interest with IT but creates a different problem: the CFO's primary concern is financial performance, which may create pressure to minimize security investment. Additionally, CFO reporting reduces operational coordination with IT, which is necessary for effective security program execution.
- Move the CISM to report to the Chief Legal Officer (CLO), as legal and compliance oversight ensures security concerns receive appropriate escalation.Incorrect. CLO reporting introduces a legal-centric bias to security decision-making and may reduce operational coordination with IT. It also does not directly address the board's concern about independent board-level visibility into security risks.
A dual reporting structure with operational reporting to the CIO and governance reporting to the board's audit committee balances operational effectiveness with independent board-level oversight.
8. Attackers who bypass preventive controls will dwell: What is the MOST significant business risk created by thi
- The organization will fail regulatory audits because regulators require all five CSF functions to be equally mature.Incorrect. Regulators generally require demonstrated capability in relevant areas, not equal maturity across all CSF functions. The primary risk from a weak Detect function is operational, not regulatory. While regulations may require breach notification, the detection gap creates the actual risk.
- Attackers who bypass preventive controls will dwell undetected for extended periods, increasing the scope of damage before containment can begin. ✓Correct. The NIST CSF Detect function covers continuous monitoring, anomaly detection, and detection processes. When Detect capability is weak, threats that bypass the organization's preventive controls (Protect function) are not identified, allowing attackers to remain in the environment—a concept known as dwell time. Extended dwell time directly correlates with larger breach scope, more data exfiltration, greater lateral movement, and higher incident response costs. No set of preventive controls is 100% effective; detection is the safety net.
- The organization cannot implement the Respond and Recover functions without mature Detect capabilities, leaving it unable to respond to incidents.Incorrect. While detection capability enables faster response, organizations can still implement Respond and Recover plans and capabilities even with detection gaps. Incidents are often detected through external notification (law enforcement, customers, threat intelligence) even when internal detection is weak. The primary risk is not the inability to respond but the delay between compromise and detection.
- The organization's security investment is imbalanced, meaning it overspent on preventive controls relative to detection controls.Incorrect. While investment imbalance may be a contributing factor, it is a root cause observation, not the business risk. The business risk is the operational consequence of the detection gap: extended dwell time and increased breach scope.
Weak detection capability allows attackers who bypass preventive controls to dwell undetected, increasing breach scope and incident response costs.
9. Percentage of critical vulnerabilities left unpatched: Which combination BEST fulfills both requirements?
- Number of security incidents last quarter as the risk indicator, and the percentage of security policies reviewed on schedule as the performance indicator.Incorrect. The number of incidents last quarter is a lagging indicator—it tells you about incidents that already happened, not about increasing future risk. Lagging indicators cannot serve as early warning signals. Policy review compliance is a valid performance indicator but does not represent the leading indicators needed for risk monitoring.
- Mean time to detect incidents used as the forward-looking risk indicator, and the total number of completed security awareness training sessions used as the program performance indicator.Incorrect. Mean time to detect (MTTD) is a lagging indicator—it measures detection speed after incidents occur, not the likelihood of future incidents. It is a program performance metric, not a forward-looking risk indicator. Training completion is an activity metric, not a program performance metric (it measures whether training happened, not whether the program is effective).
- Percentage of critical vulnerabilities left unpatched beyond their SLA as the KRI, and the percentage of security controls passing automated compliance checks as the KPI. ✓Correct. A Key Risk Indicator (KRI) is a forward-looking metric that signals when risk exposure is increasing, enabling proactive action before incidents occur. Unpatched critical vulnerabilities beyond SLA is an excellent KRI because it measures the organization's exposure window for exploitation—a leading indicator of breach likelihood. A Key Performance Indicator (KPI) measures how well the security program is performing against its objectives. Automated control compliance checks measure whether controls are functioning as designed, reflecting program performance.
- Number of employees who failed the latest phishing simulation as the performance indicator, and the number of currently open internal audit findings used as the key risk indicator.Incorrect. Phishing simulation failure rate is a program effectiveness metric (KPI), not a risk indicator. Open audit findings could be a KRI, but it measures compliance gaps, not dynamic risk exposure. This combination inverts the appropriate use and misses the most valuable leading risk indicators.
KRIs are forward-looking signals of increasing risk (e.g., unpatched critical vulnerabilities); KPIs measure program performance (e.g., control compliance rates). Both are needed in governance dashboards.
10. Lead with the organization's current risk posture relative: What is the MOST effective structure for this repo
- Present all four data points side by side as separate metrics of equal weight and importance, allowing individual board members to interpret the numbers and draw their own conclusions about which of these risks should take the highest strategic priority.Incorrect. Presenting unweighted metrics without synthesis requires the board to have security expertise they don't have. The CISM's role is to synthesize information into a coherent risk narrative and prioritized recommendations, not to present raw data for board interpretation.
- Focus the presentation almost exclusively on the three recent ransomware incidents at peer organizations to vividly illustrate the current threat environment, and use that narrative as the central justification for the security budget increase request.Incorrect. Using peer incidents as the primary reporting frame is fear-based communication that does not inform the board about the organization's specific risk posture or what decisions they need to make. Boards need information about their organization's risk, not a recounting of what happened to others.
- Provide the board with a comprehensive technical appendix containing all of the underlying vulnerability and detection data up front, and then verbally summarize the most important findings for the directors during the compressed ninety-minute board meeting itself as time permits.Incorrect. Board members are not security technicians and a technical appendix-first structure will lose their attention before reaching the strategic content. Board reports should lead with business-level risk assessment and strategic decisions, with technical detail available as backup.
- Lead with the organization's current risk posture relative to its risk appetite, highlight the unreviewed cyber insurance coverage as a material risk requiring a board decision, benchmark performance against industry peers, and propose specific risk treatment options. ✓Correct. Board reports must be structured for decision-makers with limited technical background: (1) Risk posture vs. risk appetite—the board needs to know if the organization is within its defined risk boundaries. (2) Material risks requiring board decision—the unreviewed cyber insurance is a governance and financial risk that requires board-level action. (3) Benchmarking—the MTTD comparison to industry median contextualizes performance. (4) Proposed options—boards decide, CISMs recommend. This structure informs and enables decisions within 90 minutes.
Board reports should lead with risk posture vs. appetite, highlight decisions requiring board action, benchmark against peers, and present prioritized options—structured for decision-makers, not technicians.
11. Update the AUP to cover current use cases such as cloud: What should the CISM do FIRST?
- Update the AUP to cover current use cases such as cloud storage and remote work, work with Legal and HR to make it enforceable, require every employee to formally acknowledge it, and establish a review cycle. ✓Correct. Policy updates require: (1) Content revision to reflect current technology and work patterns (cloud storage, BYOD, remote work), (2) Legal review to ensure enforceability and alignment with employment law, (3) HR coordination for employee acknowledgment processes and disciplinary framework, (4) Formal employee acknowledgment (typically annual electronic signature) to establish that employees received, read, and agreed to the policy, (5) A defined review cycle (typically annual) to prevent the four-year gap from recurring. The acknowledgment issue raised by Legal must be resolved before the policy can be enforced.
- Immediately block all personal cloud storage services across the corporate network in order to eliminate the specific risks that the outdated Acceptable Use Policy currently fails to address today.Incorrect. Blocking services without policy update and communication is a reactive technical control that does not address the governance problem. Employees may find workarounds, and the absence of a current enforceable policy means violations cannot be disciplined. Technical controls should follow policy, not replace it.
- Report the AUP gap directly to the CEO and request dedicated funding to purchase a policy management platform that automates the distribution, acknowledgment tracking, and version control of the organization's corporate policies.Incorrect. A policy management platform is a useful tool for large organizations, but purchasing a platform is not the first action. The most urgent needs are updating the policy content and establishing enforceability—actions that can be accomplished without a dedicated platform.
- Conduct a security audit to determine exactly how many employees are already using unauthorized cloud services, and then use those quantified findings to build the justification for updating the Acceptable Use Policy.Incorrect. An audit to find violators before the policy is updated and enforced creates an adversarial situation where employees may be disciplined for behavior that was not clearly prohibited by an enforceable policy. The policy update and acknowledgment must precede enforcement actions.
AUP updates require content revision, legal review for enforceability, HR coordination for disciplinary backing, formal employee acknowledgment, and a defined review cycle.
12. Implement a unified control framework that maps controls: What is the MOST effective approach to managing this
- Prioritize the most stringent framework (ISO 27001) and implement only those controls, arguing that compliance with a higher standard implies compliance with less stringent frameworks.Incorrect. Framework requirements are not strictly hierarchical. ISO 27001 is a management system standard; PCI DSS has specific technical requirements for cardholder data environments; HIPAA has specific privacy and breach notification requirements. No single framework fully encompasses all others. This approach would create compliance gaps.
- Implement a unified control framework that maps controls to multiple regulatory requirements simultaneously, so a single control implementation satisfies multiple frameworks. ✓Correct. A unified control framework (sometimes called an integrated compliance framework or common controls framework) maps each security control to all applicable regulatory requirements. When a control is implemented and tested once, the evidence satisfies multiple frameworks simultaneously. For example, access control logging satisfies HIPAA audit controls, PCI DSS requirement 10, SOC 2 CC6.1, and ISO 27001 A.9. This approach eliminates redundant audit evidence collection, reduces compliance fatigue, and ensures consistent control implementation. Tools like the HITRUST CSF are specifically designed for healthcare organizations managing multiple frameworks.
- Hire a dedicated compliance officer for each framework to ensure expert management of each regulatory requirement.Incorrect. Separate compliance teams for each framework perpetuate the siloed approach that is causing the current overload. Each team would implement controls independently, creating redundancy and inconsistency. Adding headcount without changing the approach does not solve the structural problem.
- Obtain only the compliance certifications that customers contractually require and deprioritize frameworks without contractual obligations.Incorrect. HIPAA compliance is a legal requirement, not a contractual preference—it cannot be deprioritized. PCI DSS is required for payment processing. Deprioritizing regulatory requirements based on contractual pressure misunderstands the nature of legal obligations and creates regulatory risk.
A unified control framework maps each control to multiple regulatory requirements so a single implementation and test satisfies multiple frameworks simultaneously, eliminating redundant compliance activities.
119 more Information Security Governance questions
The remaining 119 questions in this domain are part of the full CISM bank — 497 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISM readiness — freeOther CISM domains
- Information Security Risk Management — 124 questions →
- Information Security Program — 124 questions →
- Incident Management — 118 questions →
- All 497 CISM questions →