Courseiva

CISM Information Security Program Practice Question

A CISO is establishing an information security governance framework to ensure that security activities are aligned with business strategy. The organization has multiple business units, each with its own IT and security staff. Which of the following is the MOST effective way to ensure ongoing alignment?

⚠ Common exam trap

The trap here is assuming that technical measures like training or penetration testing alone can achieve strategic alignment, when governance requires cross-functional oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a security steering committee composed of business unit leaders and the CISO.

A security steering committee that includes business unit leaders and the CISO provides a governance structure where security decisions are made collaboratively and aligned with business strategy. It ensures that security is not an isolated IT function but an integral part of business operations, enabling continuous alignment and effective risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct an annual penetration test to identify and prioritize vulnerabilities.

    Why it's wrong here

    Penetration testing is a technical assessment that identifies vulnerabilities, but it does not ensure ongoing strategic alignment between security and business objectives. It is a point-in-time activity and does not address governance, communication, or resource allocation. It should be part of a broader program, not the primary alignment mechanism.

  • ✓

    Create a security steering committee composed of business unit leaders and the CISO.

    Why this is correct

    A security steering committee with business unit leaders ensures that security priorities are directly linked to business objectives. It provides a forum for discussing risks, allocating resources, and making decisions that balance security needs with business goals. This structure promotes accountability and continuous alignment, which is essential for effective governance.

  • ✗

    Delegate all security decisions to the IT department to ensure technical consistency.

    Why it's wrong here

    Delegating security decisions solely to IT may lead to solutions that are technically sound but not aligned with business needs. Business units may have different risk tolerances and priorities. Without business input, security initiatives may be perceived as obstacles rather than enablers, reducing overall effectiveness and alignment with strategic objectives.

  • ✗

    Implement a monthly security awareness training program for all employees.

    Why it's wrong here

    Security awareness training is important for reducing human risk, but it does not provide the governance structure needed to align security with business strategy. Training alone does not facilitate decision-making, resource allocation, or strategic prioritization across business units. It is a tactical control, not a governance mechanism.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.