Courseiva

CISM Information Security Governance Practice Question

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that the framework will effectively manage risk and comply with regulations such as GDPR and PCI DSS. Which of the following are essential components of an effective information security governance framework? (Choose two.)

⚠ Common exam trap

The trap here is selecting operational capabilities like a SOC or asset inventory as essential governance components, when governance is about direction and oversight, not operational execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A comprehensive set of security policies and standards.

An effective information security governance framework must include a documented risk appetite statement approved by executive management and a comprehensive set of security policies and standards. The risk appetite guides risk-based decisions and ensures alignment with business strategy, while policies and standards establish the rules and expectations for protecting information. These components provide direction, oversight, and accountability, which are the hallmarks of governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A comprehensive set of security policies and standards.

    Why this is correct

    Security policies and standards are fundamental to governance. They establish the rules and expectations for protecting information assets and ensure consistent implementation of controls. They also provide a basis for compliance and audit. Without them, security efforts are ad hoc and lack formal structure. They are a key mechanism for communicating management's directives.

  • ✗

    A formal security awareness and training program for all employees.

    Why it's wrong here

    Security awareness training is an important control to reduce human risk, but it is not an essential component of the governance framework. Governance sets the direction and oversight; awareness is an operational activity that supports policy compliance. While it may be required by regulations, it is not a foundational element of governance itself. The framework can exist without it, though it would be less comprehensive.

  • ✗

    A real-time security operations center (SOC) with 24/7 monitoring.

    Why it's wrong here

    While a SOC is a valuable operational capability, it is not an essential component of the governance framework itself. Governance focuses on direction, oversight, and accountability. A SOC is a technical control that supports incident detection and response, but it is not required for governance. Governance can exist without a SOC, though it may be necessary for effective risk management in some organizations.

  • ✓

    A documented risk appetite statement approved by executive management.

    Why this is correct

    A risk appetite statement defines the level of risk the organization is willing to accept in pursuit of its objectives. It is essential for governance as it guides decision-making and ensures that security activities are aligned with business strategy. Without it, risk management lacks direction and may not reflect the board's tolerance. It also provides a basis for measuring and monitoring risk.

  • ✗

    A detailed inventory of all IT assets with assigned owners.

    Why it's wrong here

    An asset inventory is important for risk management and security operations, but it is not a core component of the governance framework. Governance provides the structure for managing risk, but the inventory is a supporting process. While valuable, it is not essential for the framework's existence. Governance can be established without a complete inventory, though it would be less effective.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.