CISM Information Security Governance Practice Question
A CISO is updating the organization's information security policy to reflect a new regulatory requirement. The policy must be approved before it can be communicated to employees. Who is MOST appropriate to approve the updated policy?
⚠ Common exam trap
The trap here is assuming the board or CISO must approve all policy updates, when in practice executive management holds the delegated authority for operational policy approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The executive management committee or a designated senior executive, such as the CIO or COO.
Executive management or a designated senior executive is the most appropriate approver for an updated security policy because they have the authority to enforce it across the organization and ensure it aligns with business strategy. While the board is accountable and legal should review, operational policy approval is typically delegated to executives to enable timely updates and practical implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The executive management committee or a designated senior executive, such as the CIO or COO.
Why this is correct
Executive management, such as the CIO or COO, is typically responsible for approving security policies to ensure they align with business objectives and have the authority for enterprise-wide enforcement. This level of approval balances operational practicality with strategic oversight. It also demonstrates management commitment to security, which is essential for compliance and culture. The board remains accountable but delegates this authority.
- ✗
The board of directors, because they have ultimate accountability for regulatory compliance.
Why it's wrong here
While the board has ultimate accountability, policy approval at that level is impractical for every update. The board typically approves the overarching security strategy and risk appetite, not detailed policy documents. Delegating policy approval to executive management ensures timely updates and operational relevance. Involving the board for every regulatory change would slow the process and is not aligned with typical governance structures.
- ✗
The chief information security officer (CISO), as the owner of the security program.
Why it's wrong here
The CISO is responsible for developing and maintaining the security policy, but approval by the CISO alone may lack the executive authority needed to enforce it across the organization. Policy approval should involve business leadership to ensure alignment and buy-in. In many governance models, the CISO drafts the policy but does not have the final approval authority, which typically rests with an executive committee or senior management.
- ✗
The legal department, because the policy is driven by a regulatory requirement.
Why it's wrong here
Legal should review the policy for regulatory compliance, but they are not the appropriate approvers. Approval requires business and security leadership to ensure the policy is implementable and aligned with organizational goals. Legal's role is advisory, not authoritative, for security policy. Relying solely on legal approval could result in a policy that is compliant but not operationally effective or embraced by the business.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.