hardMultiple ChoiceObjective-mapped
Best Governance Committee Composition
A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?
Quick Answer
The answer is a governance committee composed of senior leaders from each business unit, the CISO, and the Chief Risk Officer. This composition best ensures alignment between security and business strategy because it creates a cross-functional governance body that integrates diverse operational perspectives with risk and security expertise, enabling strategic decisions that balance protection with business objectives. On the CISM exam, this tests your understanding of governance committee membership best composition as a core concept of information security governance, often appearing in questions that contrast broad business representation with narrow functional groups. A common trap is choosing IT-heavy or finance-only memberships, which lack the authority and business context needed for true strategic alignment. Remember the memory tip: “Three pillars of governance—business, security, and risk”—ensuring every major stakeholder voice is at the table.
⚠ Common exam trap
Many exam-takers assume a committee composed solely of IT and security roles (like the CISO and IT directors) is sufficient, but CISM emphasizes that governance requires cross-functional senior leadership to ensure security is a business enabler, not just a technical function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Senior leaders from each business unit, the CISO, and the Chief Risk Officer
It ensures that the information security governance committee includes senior leaders from each business unit, the CISO, and the Chief Risk Officer. This composition directly aligns security initiatives with business strategy by integrating business objectives, risk appetite, and security expertise at the strategic decision-making level, which is essential for effective governance as defined by ISACA's CISM framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT operations managers and the CISO
Why it's wrong here
Too focused on IT, not business.
- ✗
Chief Information Security Officer (CISO) and IT directors only
Why it's wrong here
Excludes business stakeholders.
- ✓
Senior leaders from each business unit, the CISO, and the Chief Risk Officer
Why this is correct
Ensures business alignment and risk integration.
- ✗
Chief Financial Officer (CFO), General Counsel, and CISO
Why it's wrong here
Lacks representation from operational business units.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?
medium- A.Data breaches will occur more frequently
- ✓ B.Security policies may not align with operational processes
- C.Security spending will increase unexpectedly
- D.The company will face regulatory fines
Why B: Without Business Operations representation, the security steering committee lacks direct insight into how security policies will interact with day-to-day operational workflows. This gap often results in policies that are technically sound but impractical to implement, causing misalignment with existing processes and potential operational friction.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.