mediumMultiple Choice
CISM Practice Question: A company's security steering committee includes…
A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?
⚠ Common exam trap
ISACA CISM exams often test the distinction between governance-level gaps (like missing stakeholder representation) and operational-level failures (like breaches or fines), tempting candidates to pick dramatic outcomes rather than the more subtle but direct consequence of policy misalignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policies may not align with operational processes
Without Business Operations representation, the security steering committee lacks direct insight into how security policies will interact with day-to-day operational workflows. This gap often results in policies that are technically sound but impractical to implement, causing misalignment with existing processes and potential operational friction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data breaches will occur more frequently
Why it's wrong here
Breach frequency depends on control effectiveness and threat activity, not on who sits on a governance body. Excluding Business Operations weakens alignment between security strategy and operational reality, delaying remediation and ownership. Frequent breaches would follow from missing technical controls, not from this membership gap.
- ✓
Security policies may not align with operational processes
Why this is correct
Without Business Operations representation, the committee lacks visibility into how work is actually performed, so policies risk conflicting with or ignoring real operational workflows. This membership gap directly produces the misalignment described, since operational processes are neither represented nor validated during policy approval.
- ✗
Security spending will increase unexpectedly
Why it's wrong here
Steering committees allocate budget and prioritise controls; omitting Business Operations removes the function that owns most processes and funding requests, producing misaligned or delayed investment rather than automatic increases. Spending rises unpredictably only when security initiatives bypass governance and are approved ad hoc outside the committee.
- ✗
The company will face regulatory fines
Why it's wrong here
Regulatory fines follow a demonstrated compliance failure, such as a reportable breach or audit finding, not committee composition. Legal and Risk Management representation already covers obligation tracking. Fines would be the likely outcome if those functions were absent and applicable requirements went unmonitored.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.