CISM Information Security Governance Practice Question
A global financial services firm is establishing an information security governance framework. The board of directors wants assurance that security risks are managed effectively across all business units. Which of the following is the MOST important element for the CISO to implement to provide this assurance?
⚠ Common exam trap
The trap here is focusing on technical controls like SOCs or penetration tests as the primary means of assurance, when governance requires an organizational structure that ensures oversight and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security governance committee with representation from all business units, reporting to the board.
The most important element is a security governance committee with representation from all business units, reporting to the board. This committee provides the structure for consistent risk management, oversight, and accountability across the organization. It ensures that security risks are considered in business decisions and gives the board a direct line of sight into how risks are being managed, which is essential for effective governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A security governance committee with representation from all business units, reporting to the board.
Why this is correct
A governance committee with cross-functional representation ensures that security risks are considered in all business decisions and provides a direct reporting line to the board. This structure enables oversight, accountability, and consistent risk management across units. It is the most important element because it establishes the organizational mechanism for governance, rather than just technical controls.
- ✗
A security awareness program for all employees.
Why it's wrong here
Security awareness reduces human error but does not assure the board that risks are managed at the governance level. It is an important control, but it does not establish accountability, oversight, or alignment with risk appetite across business units. The board requires a structural mechanism to ensure consistent risk management, which awareness training alone cannot provide.
- ✗
An annual penetration test of all critical systems.
Why it's wrong here
Penetration testing is a point-in-time assessment of technical vulnerabilities. While valuable, it does not provide ongoing assurance that risks are managed across business units. It lacks the governance and oversight components needed to assure the board that risk management is integrated into business processes and decision-making.
- ✗
A centralized security operations center (SOC) that monitors all network traffic.
Why it's wrong here
A centralized SOC provides detection and response capabilities, but it does not directly assure the board that security risks are managed across all business units. Monitoring traffic is a technical control, not a governance mechanism. The board needs visibility into risk management decisions, accountability, and alignment with risk appetite, which a SOC alone does not deliver.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.