CISM Information Security Governance Practice Question
A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?
⚠ Common exam trap
CISM often tests exception management, and candidates may focus on approval authority rather than the need for a documented remediation plan and risk acceptance, which is the core of the process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A documented remediation plan with timelines and risk acceptance
The most important element of an exception management process is a documented remediation plan with timelines and formal risk acceptance. This ensures that the exception is temporary, that the risk is understood and accepted by the appropriate authority, and that there is a clear path to compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notification to all employees
Why it's wrong here
Broad employee notification is communication, not governance; it neither assesses the legacy system's risk nor authorises the deviation. It would be appropriate for awareness campaigns after an approved exception. The essential element is documented risk assessment, time-bound approval, and compensating controls with review.
- ✗
Annual renewal without further review
Why it's wrong here
Automatic annual renewal without review defeats the exception's temporary nature, letting unassessed risk persist indefinitely. It would be acceptable only where the underlying system and threat landscape are unchanged and re-validation confirms residual risk. Exceptions require periodic reassessment, expiry dates, and closure once remediated.
- ✗
Approval by the CISO only
Why it's wrong here
CISO-only approval concentrates authority in one role, omitting the business owner and data owner whose risk acceptance and compensating controls justify the exception. It would suffice only for low-impact, single-domain deviations. The process needs documented risk acceptance, defined scope and expiry, and monitoring.
- ✓
A documented remediation plan with timelines and risk acceptance
Why this is correct
A documented remediation plan with timelines and risk acceptance satisfies the stem's temporary non-compliance constraint by ensuring the legacy system's encryption gap is formally owned, time-bound, and reviewed. Risk acceptance transfers accountability to the appropriate authority, preventing the exception from becoming permanent, undocumented drift.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.