20+ practice questions focused on Information Security Governance — one of the most tested topics on the Certified Information Security Manager CISM exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Information Security Governance PracticeDuring a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?
Explanation: After a policy is drafted, the immediate next step is legal review to ensure the policy complies with applicable laws, regulations, and contractual obligations. This is critical because policies often impose mandatory requirements, and legal counsel must verify that they do not conflict with legal constraints or create unintended liabilities. Only after legal clearance should the policy proceed to broader stakeholder consultation and formal approval.
A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?
Explanation: SOX (B) is correct because the Sarbanes-Oxley Act imposes mandatory financial reporting, internal control, and IT audit/record-retention requirements on publicly traded U.S. companies, which squarely covers a U.S. financial services firm. PCI DSS (C) is correct because any financial services company that stores, processes, or transmits cardholder data (e.g., credit/debit card payments) must comply with the Payment Card Industry Data Security Standard. Sector-specific regulations such as SEC cybersecurity rules (D) are correct because U.S. financial institutions are directly regulated by agencies like the SEC, FINRA, and the Federal Reserve, which mandate cybersecurity risk management, incident disclosure, and related controls. HIPAA (A) does not belong because it governs protected health information held by healthcare providers, plans, and clearinghouses, not financial services. GDPR (E) does not belong because it applies to processing of EU residents' personal data by organizations in the EU or targeting EU data subjects, not specifically to a U.S.-operating financial services company.
Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?
Explanation: Level 4 (Managed) is characterized by quantitative management of processes.
An organization is updating its security policies. After drafting the policy, which step should occur NEXT?
Explanation: After a policy is drafted, the next step in the policy lifecycle is legal review to ensure the policy does not conflict with laws, regulations, contracts, or other binding obligations before it is submitted for management approval. Legal review is a prerequisite to approval because management must sign off on a document that is legally sound. Only after legal clearance should the policy go to management for formal approval.
A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?
Explanation: Option D (Security investment vs. loss avoidance) is correct because it expresses security spending in financial, risk-adjusted terms that directly map to the board's fiduciary concerns about cost-benefit and return on security investment, enabling governance decisions on budget allocation. Option E (Mean time to respond, MTTR) is correct because it is a strategic resilience indicator showing how quickly the organization contains and recovers from incidents, which boards use to gauge operational risk exposure and the effectiveness of the security program. The unmarked options do not belong at board level: A (phishing simulation click rate) and B (average patch deployment time) are tactical/operational metrics better suited to security managers and operational teams, and C (number of firewall rules) is a low-level technical configuration count with no meaningful risk or business context for executive governance.
+15 more Information Security Governance questions available
Practice all Information Security Governance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Information Security Governance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Information Security Governance questions on the CISM frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Information Security Governance is tested as part of the Certified Information Security Manager CISM blueprint. Practicing with targeted Information Security Governance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CISM practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Information Security Governance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Information Security Governance practice session with instant scoring and detailed explanations.
Start Information Security Governance Practice →