CISM Information Security Governance Practice Question
A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)
⚠ Common exam trap
The trap here is equating governance with operational capabilities or technologies, rather than focusing on the structural and process elements that define oversight and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A clear definition of security roles and responsibilities across the organization.
An effective security governance framework must include clear roles and responsibilities to ensure accountability, and a process for regularly updating policies to adapt to changes. These components provide the structure and adaptability needed to align security with business objectives and manage risk. Advanced technologies, centralized decision-making, and operational centers are not core governance elements; they are tactical or operational considerations that support the framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The use of advanced security technologies such as AI-based threat detection.
Why it's wrong here
While advanced technologies can enhance security, they are not an essential component of a governance framework. Governance focuses on direction, oversight, and accountability, not specific tools. Technologies are selected and implemented based on risk and business needs, but they do not define the framework itself.
- ✗
A requirement that all security decisions be made by the CISO without business input.
Why it's wrong here
Effective governance requires collaboration between security and business units. Centralizing all decisions with the CISO can lead to misalignment with business objectives and lack of buy-in. Governance should ensure that security supports the business, which requires input from various stakeholders.
- ✓
A clear definition of security roles and responsibilities across the organization.
Why this is correct
Clearly defining security roles and responsibilities is essential for accountability and effective governance. It ensures that every aspect of the security program has an owner, preventing gaps and overlaps. This clarity also enables better communication and coordination between business units and the security team, aligning security activities with business goals.
- ✗
The implementation of a security operations center (SOC) to monitor for threats 24/7.
Why it's wrong here
A SOC is an operational capability, not a governance component. While monitoring is important, governance is about strategic direction and oversight. A SOC may be part of the security program, but it is not essential to the governance framework itself. The framework should define how security is governed, not the specific operational structures.
- ✓
A process for regularly reviewing and updating security policies to reflect changes in the threat landscape.
Why this is correct
Regular review and updating of security policies is critical to ensure they remain relevant and effective. The threat landscape, business environment, and regulatory requirements evolve, so policies must be dynamic. This process demonstrates proactive governance and helps maintain compliance and risk management over time.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.