CISM Information Security Governance Practice Question
A global financial services firm is aligning its information security program with the COBIT framework. The board wants assurance that IT risks are governed effectively. Which COBIT component is MOST directly responsible for ensuring that IT risk management activities are aligned with enterprise risk management?
⚠ Common exam trap
The trap here is assuming that any risk-related process, such as APO12, fulfills the governance requirement, when only the evaluate, direct, and monitor domain provides board-level alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EDM03 Ensured Risk Optimization
EDM03 is part of the governance domain in COBIT and specifically ensures that IT risk management is integrated with enterprise risk management, including setting risk appetite and tolerance. This directly addresses the board's need for assurance that IT risks are governed effectively and aligned with overall enterprise risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MEA03 Managed Compliance with External Requirements
Why it's wrong here
MEA03 focuses on evaluating whether IT processes comply with external laws, regulations, and contracts. It is a monitoring and evaluation process, not a governance process for aligning IT risk management with enterprise risk management, so it does not fulfill the board's requirement.
- ✗
DSS05 Managed Security Services
Why it's wrong here
DSS05 is a management domain process that deals with delivering security services such as identity management and vulnerability management. It is operational in nature and does not provide governance oversight or ensure alignment of IT risk with enterprise risk management.
- ✓
EDM03 Ensured Risk Optimization
Why this is correct
EDM03 is a governance domain process in COBIT that ensures IT-related risk management is aligned with enterprise risk management and that risk appetite is understood and communicated. It directly addresses board-level oversight of risk optimization, making it the most direct component for aligning IT risk with enterprise risk.
- ✗
APO12 Managed Risk
Why it's wrong here
APO12 is a management domain process that focuses on identifying, assessing, and mitigating IT-related risks on an ongoing basis. While it supports risk management, it operates at the management level and does not directly ensure alignment with enterprise risk management, which is a governance responsibility.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.