Courseiva

CISM Information Security Governance Practice Question

A CISO is designing a security governance framework for a multinational corporation. The framework must address the need for clear accountability, alignment with business strategy, and effective risk management across diverse business units. Which TWO of the following are essential components of such a governance framework? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse operational or technical elements, such as a SOC or penetration testing, with governance components, which are about structure, accountability, and strategic alignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A process for regularly reviewing and updating security policies to reflect changes in the threat landscape and business environment.

A defined security organizational structure and a process for regularly reviewing policies are essential governance components. The structure ensures accountability and clear roles, while the policy review process ensures ongoing alignment with business strategy and emerging risks. These elements provide the foundation for effective decision-making and oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A process for regularly reviewing and updating security policies to reflect changes in the threat landscape and business environment.

    Why this is correct

    Regular review and updating of security policies ensures that they remain relevant and effective as the organization, threats, and regulations evolve. This process is essential for maintaining alignment with business strategy and managing emerging risks. It demonstrates proactive governance and helps prevent policies from becoming outdated or ineffective, which could lead to compliance issues or security gaps.

  • ✗

    A comprehensive set of technical security controls, such as firewalls and intrusion detection systems.

    Why it's wrong here

    Technical controls are implementation mechanisms, not governance components. Governance provides the direction and oversight for selecting and managing controls, but the controls themselves are not part of the governance framework. The question asks for governance components, which are about structure, processes, and accountability, not specific technologies.

  • ✓

    A defined security organizational structure with clearly assigned roles and responsibilities.

    Why this is correct

    A defined organizational structure with clear roles and responsibilities ensures accountability and avoids gaps or overlaps in security duties. It establishes who is responsible for what, enabling effective decision-making and coordination across business units. This is a foundational element of governance because it provides the framework for executing security strategy and managing risk consistently.

  • ✗

    A centralized security operations center (SOC) that monitors all security events 24/7.

    Why it's wrong here

    While a SOC is important for detection and response, it is an operational component, not a governance component. Governance focuses on decision-making, oversight, and accountability. A SOC does not define roles, responsibilities, or strategic alignment. It supports the execution of security but does not constitute a governance framework element. Thus, it is not essential for the governance framework itself.

  • ✗

    An annual penetration test to validate the effectiveness of security controls.

    Why it's wrong here

    Penetration testing is a validation activity that supports governance by providing assurance, but it is not a governance component itself. Governance frameworks include elements like roles, policies, and risk management processes. Testing is an operational task that should be governed, but it does not define the governance structure. Therefore, it is not an essential component of the governance framework.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.