CISM Information Security Governance Practice Question
A financial services company is updating its information security policies to reflect a new regulation. The CISO must ensure the policies are effectively communicated and enforced. Which action is MOST important to achieve this?
⚠ Common exam trap
The trap here is assuming that simply publishing or emailing policies is enough to ensure compliance, when active training and acknowledgment are required for enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain executive management approval and communicate the policies with mandatory training and acknowledgment.
The correct answer is to obtain executive approval and communicate with mandatory training and acknowledgment. In CISM, policy governance requires that policies are authorized at the highest level and then effectively communicated. Training ensures employees understand their responsibilities, and acknowledgment provides evidence of compliance. This approach ensures the policies are enforced and can be audited, which is essential for regulatory compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include the policies in the employee handbook and require new hires to sign them during onboarding.
Why it's wrong here
While including policies in the handbook and onboarding is good practice, it only covers new hires and does not address existing employees. It also lacks the active training and acknowledgment needed to ensure understanding. For a regulatory update, all relevant staff must be trained and acknowledge the changes, not just new hires.
- ✓
Obtain executive management approval and communicate the policies with mandatory training and acknowledgment.
Why this is correct
This is correct because CISM emphasizes that policies must be approved by executive management to have authority, and then communicated through training and acknowledgment to ensure understanding and compliance. Mandatory training and acknowledgment create accountability and provide evidence of enforcement. This combination ensures the policies are not just published but actively adopted across the organization.
- ✗
Ask department managers to verbally brief their teams on the policy changes during staff meetings.
Why it's wrong here
Verbal briefings are inconsistent and not auditable. They do not provide evidence of acknowledgment or understanding, and they may not cover all employees. For effective policy communication and enforcement, a formal, documented process with training and acknowledgment is required. Verbal briefings alone are insufficient for compliance and governance.
- ✗
Publish the updated policies on the corporate intranet and send an email announcement to all staff.
Why it's wrong here
Publishing and emailing are communication methods, but they do not ensure understanding or enforcement. Policies must be socialized through training, acknowledgment, and integration into processes. Without these, employees may ignore or misinterpret the policies, and enforcement becomes difficult. This action alone is insufficient for effective governance.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.