CISM domain 1, Information Security Governance, is about how an organisation makes decisions and assigns responsibility for protecting its data and systems. This chapter covers Governance Roles, Responsibilities, and Reporting—the human side of security that defines exactly who does what and how information flows upward. For the CISM exam, you need to understand that security is not just a technology problem; it is a people-and-process problem, and getting the roles wrong is one of the fastest ways to fail an audit or miss a real breach.
Jump to a section
A simple way to picture Governance Roles, Responsibilities, and Reporting
The Chief of Staff at a large hospital never performs surgery on a patient or takes a blood sample herself. Her job is to make sure the right people with the right skills are in the right place at the right time, and that every doctor and nurse knows who to report to when something goes wrong. She creates the policies—like which surgeon handles which type of operation—and she ensures every staff member understands their specific duties. When a new regulation about patient data privacy comes from the government, she calls a meeting of department heads, explains what needs to change, and then holds each department leader accountable for updating their procedures. If a junior doctor notices a broken sterilisation machine, they know to report it to their shift supervisor, who reports to the head of surgery, who reports to the Chief of Staff. There is no confusion about who handles what. The Chief of Staff does not fix the machine—that is the biomedical engineer’s job—but she makes sure someone does. She also sends a monthly report to the hospital board about safety incidents, staffing changes, and policy updates. This clear chain of command, defined responsibilities, and structured reporting keeps the hospital running safely and efficiently. In the same way, information security governance is not about an IT manager personally fixing every firewall or resetting every password. It is about defining who is responsible for what, who has the authority to make decisions, and how information about security risks and incidents flows upward to the people who can act on it.
Without this structure, the hospital—or the company—descends into chaos, with critical tasks left undone because nobody knows they are the one who should do them.
Governance, in the context of information security, means the system by which an organisation’s security activities are directed and controlled. It is not about the day-to-day technical tasks like configuring a firewall or patching a server. Instead, governance is about setting the overall direction, establishing policies, and ensuring that everyone in the organisation—from the boardroom to the help desk—knows what they are responsible for and who they report to. This chapter focusses on three interconnected pieces: roles, responsibilities, and reporting.
First, let us define a role. A role is a function or job that someone performs within the security governance structure. For example, the Chief Information Security Officer (CISO) is a role. The board of directors is a role. The data owner is a role. A responsibility is the duty or task that comes with that role. For example, the CISO’s responsibilities include developing the security strategy and reporting to senior leadership. The data owner’s responsibilities include classifying data and deciding who can access it. Reporting is the process of communicating information about security status, risks, and incidents upward through the organisation, typically from operational staff to management to the board.
Why does an organisation need this structure? Without clear governance roles, you get confusion. If a data breach happens, no one knows who is supposed to lead the response. If a new security policy is needed, no one knows who has the authority to approve it. If the board asks for a security update, no one knows who should compile the report. This confusion leads to delays, increased risk, and often regulatory non-compliance.
The typical governance hierarchy looks like this:
The board of directors: This is the highest level. The board has ultimate oversight responsibility for the organisation, including security. They do not manage security day-to-day, but they must ensure the organisation has an effective security program. They approve the overall security strategy and budget.
The executive leadership (CEO, CFO, etc.): These senior leaders are responsible for integrating security into the organisation’s operations. The CEO is ultimately accountable for security outcomes, even though they delegate the work to others.
The Chief Information Security Officer (CISO): This is the senior leader specifically responsible for the information security program. The CISO develops the strategy, manages the security team, and reports to the board and executive leadership on security matters. The CISO is the key decision-maker for security operations.
The information security steering committee: This is a cross-functional group (often including representatives from IT, legal, HR, and business units) that meets regularly to review security initiatives, approve policies, and prioritise projects. It provides oversight and ensures security aligns with business goals.
The data owner: This is a business manager who is responsible for a specific set of data. For example, the head of HR is the data owner for employee records. The data owner decides who can access the data and what level of protection it needs.
The data custodian: This is an IT role (often a database administrator or system administrator) who is responsible for implementing the technical controls that protect the data. They manage backups, access controls, and encryption, but they do not decide who gets access—the data owner decides.
The security manager or security team lead: This role oversees the day-to-day security operations, such as monitoring logs, responding to incidents, and managing security tools. They report to the CISO.
The user: Every employee who uses the organisation’s systems has a responsibility to follow security policies, report suspicious activity, and protect their credentials.
Reporting is the mechanism that connects these roles. The operational security team reports incidents to the security manager. The security manager reports summary information to the CISO. The CISO reports high-level status, risks, and compliance information to the board. This reporting often happens through structured reports, dashboards, and regular meetings. For example, a CISO might present a quarterly report to the board that includes key metrics like the number of incidents, the status of critical vulnerabilities, and progress on security projects. The board uses this information to make decisions about budget and strategy.
This governance structure replaces an older, less formal approach where security was often an afterthought handled entirely by the IT department. In the old model, the IT manager might have been responsible for everything security-related, from policies to patching, and reporting was informal. That model fails because IT managers lack the authority to enforce policies across the entire organisation, and they do not have direct access to the board. The modern governance model formalises roles, creates clear accountability, and ensures security is treated as a business issue, not just a technical one.
Identify the governing body
The first step is to identify who at the top of the organisation is accountable for security decisions. This is typically the board of directors. They set the risk appetite and approve the security strategy. Without this step, there is no ultimate authority.
Appoint a senior security leader (CISO)
The board or CEO appoints a CISO to act as the single point of responsibility for the security program. The CISO develops policies, manages the team, and reports back to the board. This creates a clear link between strategy and execution.
Define data ownership and custodianship
The organisation identifies every major set of data (customer records, financial data, HR files) and assigns a business manager as data owner. IT staff are designated as data custodians. This clarifies who decides access and who implements it.
Form a security steering committee
A cross-functional group is created, including the CISO, legal, HR, finance, and business unit leaders. This committee reviews security initiatives, approves policies, and ensures alignment with business goals. It provides oversight between the CISO and the board.
Establish reporting lines and cadence
Define how often security information is reported and to whom. For example, the CISO provides a quarterly report to the board, a monthly dashboard to the steering committee, and incident reports are triggered by severity. This ensures the right people get the right information at the right time.
Document and communicate the governance framework
The final step is to write down the roles, responsibilities, and reporting structure in a governance charter or policy document. This is then communicated to all employees so everyone knows who to go to with security questions or issues. This prevents ambiguity.
Consider a medium-sized company called Acme Financial Services that processes customer loan applications and stores sensitive financial data. Acme has about 500 employees. Until last year, there was no formal security governance structure. The IT manager, Raj, handled everything: he wrote the password policy, decided who could access the database, and occasionally reported to the CEO when something broke. The board never asked about security.
Then a regulator fined Acme €50,000 because they discovered that customer data was accessible to anyone in the company with a shared login. The board panicked and demanded a change. The CEO hired a CISO, a woman named Sarah, to take charge of security. What does Sarah actually do?
First, Sarah meets with the board and explains the governance framework. She tells them that the board itself has a role: they must approve the security strategy and receive regular reports. She drafts a reporting schedule and commits to a quarterly security briefing for the board.
Next, Sarah identifies all the data owners at Acme. She meets with the head of HR, the head of loan processing, and the head of marketing. She explains that each of them is now officially the data owner for their department’s data. The head of loan processing, for example, must now decide exactly who in her team can view customer bank statements. She must document that access list. Sarah provides a template for this.
Sarah also works with Raj, the IT manager, to formally designate him as the data custodian. Raj no longer decides who gets access to the customer database—the data owners make those decisions. Raj’s new responsibility is to implement the technical controls: he sets up the database permissions based on the data owner’s instructions, he runs weekly backups, and he monitors access logs for unusual activity.
Sarah creates a security steering committee that meets monthly. The committee includes Raj, the legal counsel, a representative from HR, and the head of loan processing. At the first meeting, they review a new policy Sarah has drafted about remote work security. The committee debates the policy, suggests changes, and finally approves it. This is the governance process in action: the policy is not just Raj’s idea—it is reviewed by multiple stakeholders who understand the business impact.
Now, consider a real incident. An employee in loan processing clicks a phishing link in an email. The employee’s computer gets infected with malware. The employee immediately reports it to their manager, who reports it to the IT help desk. The help desk escalates to Raj. Raj, as the data custodian, isolates the computer from the network and begins the incident response process. He reports the incident to Sarah, the CISO, within an hour. Sarah evaluates the severity. Because the malware could have accessed customer data, she decides to notify the data owner (the head of loan processing) and the legal counsel. She also prepares a brief report for the board, summarising what happened, what data may have been affected, and what steps are being taken. She presents this at the next quarterly board meeting.
Without these defined roles, chaos would ensue. The employee might not know who to report the phishing email to. Raj might not know whether to call the CEO or the legal team. The board might find out about the incident weeks later from a newspaper article. The governance structure prevents all of that.
Sarah also implements a formal reporting process. She develops a monthly security dashboard that shows the number of phishing reports, patch compliance rates, and open vulnerabilities. She sends this dashboard to the steering committee and the CEO. She also creates a more detailed annual report for the board, covering the security program’s progress against the strategic plan.
The CISM exam tests Governance Roles, Responsibilities, and Reporting heavily. Questions in this area are designed to see if you understand who is accountable versus who is responsible, and who should be reporting to whom. The exam uses the word ‘accountability’ carefully: accountability cannot be delegated, but responsibility can be. This is a critical distinction that appears in multiple-choice questions.
Key concepts the exam loves to test:
The board of directors is accountable for security. They cannot delegate this accountability. They must approve the strategy and receive reports. A common trap question will suggest that the CISO is accountable for security—this is wrong. The CISO is responsible, but the board is accountable.
The CISO is the senior leader responsible for the security program. The exam will test that the CISO reports to senior management (like the CEO or board), not to the IT manager. Be careful: some questions place the CISO under the CIO, but the better governance answer is that the CISO should report to a level that allows independent decision-making, often to the CEO or board directly.
Data owners are business managers, not IT staff. The exam loves to test this distinction. A data owner decides on access permissions; a data custodian implements them. If a question asks who decides whether marketing can access customer data, the answer is the data owner (the head of marketing or a business executive), not a database administrator.
Reporting lines: the exam tests that security incidents should be reported up the chain, not just fixed in isolation. A correct answer will include notification to the CISO and potentially to legal and the board, depending on severity.
The steering committee: the exam will test that this committee includes representation from across the business, not just IT. Its role is to align security with business objectives.
Compliance and regulatory reporting: the exam tests that the organisation must report to regulators when required by law, and that the CISO is typically responsible for making that happen.
Common exam traps:
A question will say ‘Who is ultimately responsible for information security?’ The tempting answer is the CISO, but the exam wants ‘the board of directors’ because they have ultimate accountability.
A question will describe a scenario where a security policy needs to be created. An incorrect answer will say ‘the IT security team writes it and sends it to all employees’. The correct answer involves the steering committee reviewing and approving it, and the board being informed.
A question will test the difference between a data owner and a data custodian. The trap is to switch their roles. Memorise: data owner decides who gets access; data custodian implements the technical controls.
A question might ask who should receive a monthly security status report. The wrong answer is ‘all employees’. The right answer is senior management and the board (or the steering committee).
To prepare, focus on memorising the hierarchy: board → CEO → CISO → security team. Understand that reporting flows upward and that each layer has a specific function. Practise with scenario-based questions where you must assign roles.
The board of directors holds ultimate accountability for information security and cannot delegate it to anyone else.
The CISO is responsible for developing and managing the security program, but the board remains accountable.
Data owners are business managers who decide access permissions; data custodians are IT staff who implement those decisions.
A security steering committee must include cross-functional representation from legal, HR, finance, and business units.
Reporting flows upward: operational staff report to management, management reports to the CISO, and the CISO reports to the board.
Accountability cannot be delegated, but responsibility can be delegated to specific roles like the CISO or security manager.
The data owner classifies data and determines who can access it; the data custodian enforces the technical controls.
A formal reporting structure with dashboards and quarterly briefings ensures the board can fulfil its oversight role.
These come up on the exam all the time. Here's how to tell them apart.
Accountability
Cannot be delegated
Rests with the board of directors
Involves ultimate answerability for outcomes
Responsibility
Can be delegated to roles like the CISO
Rests with individuals who perform tasks
Involves the duty to complete assigned work
Data Owner
Typically a business manager
Decides who can access data and how it is classified
Defines access policies
Data Custodian
Typically an IT administrator
Implements technical controls like permissions and backups
Enforces access policies set by the owner
Board of Directors
Holds ultimate accountability for security
Meets infrequently (quarterly)
Approves high-level strategy and budget
Security Steering Committee
Responsible for tactical oversight
Meets monthly or bi-monthly
Reviews and approves policies and projects
CISO
Senior leader reporting to the board or CEO
Responsible for strategy and program management
Sets the overall security direction
Security Manager
Mid-level manager reporting to the CISO
Responsible for day-to-day operations
Manages incident response and security tools
Mistake
The CISO is personally accountable for all security failures.
Correct
The CISO is responsible for the security program, but accountability for security ultimately rests with the board of directors.
This mistake comes from confusing operational responsibility with governance accountability. People assume the most senior security person is the one who gets fired, but governance theory places accountability at the board level.
Mistake
Data owners are typically IT staff because they manage the systems that hold the data.
Correct
Data owners are business managers who own the data from a business perspective. IT staff are data custodians who implement the controls.
Beginners see IT staff managing databases and assume they also own the data. They miss the governance separation of duties where business decides access policy.
Mistake
Reporting means sending an email to everyone when something bad happens.
Correct
Reporting is a structured process with defined recipients (e.g., board, senior management, regulators) and defined formats (e.g., dashboards, quarterly reports).
People think of reporting as informal communication. The exam tests the formal governance reporting chain.
Mistake
The security steering committee is made up of only IT and security people.
Correct
The committee must include representatives from across the business, such as legal, HR, finance, and operations.
This misconception comes from thinking security is an IT-only problem. Governance requires business buy-in.
Mistake
If a company has a CISO, the board no longer needs to worry about security.
Correct
The board remains accountable for security oversight, even after delegating responsibility to the CISO.
People think delegation means the board can ignore security. The exam stresses that accountability is not delegable.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
Accountability means being ultimately answerable for an outcome and cannot be delegated. The board is accountable for security. Responsibility means being assigned a task or duty and can be delegated. The CISO is responsible for the security program.
The CISO should report to a senior level that gives them independence and authority, ideally the CEO or the board of directors. Reporting to the CIO or IT manager is less ideal because it can create a conflict of interest.
It reviews and approves security policies, prioritises security projects, and ensures security initiatives align with business objectives. It includes representatives from across the organisation, not just IT.
A data owner is a business manager who decides who can access their data and how it should be classified. A data custodian is an IT person who implements the technical controls (like permissions and backups) to protect that data.
No. The board is not involved in day-to-day security operations. Their role is oversight: approving strategy, reviewing reports, and ensuring the organisation has adequate resources for security.
It should include high-level metrics like number of incidents, status of critical vulnerabilities, progress against security projects, compliance status, and recommendations for additional investment. It should not include technical details.
You've finished Governance Roles, Responsibilities, and Reporting. Continue through the CISM study guide to build a complete picture of the exam.
Done with this chapter?