Courseiva

CISM Information Security Governance Practice Question

A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)

⚠ Common exam trap

The trap here is equating governance with operational capabilities or technologies, rather than focusing on the structural and process elements that define oversight and accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A clear definition of security roles and responsibilities across the organization.

An effective security governance framework must include clear roles and responsibilities to ensure accountability, and a process for regularly updating policies to adapt to changes. These components provide the structure and adaptability needed to align security with business objectives and manage risk. Advanced technologies, centralized decision-making, and operational centers are not core governance elements; they are tactical or operational considerations that support the framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The use of advanced security technologies such as AI-based threat detection.

    Why it's wrong here

    While advanced technologies can enhance security, they are not an essential component of a governance framework. Governance focuses on direction, oversight, and accountability, not specific tools. Technologies are selected and implemented based on risk and business needs, but they do not define the framework itself.

  • ✗

    A requirement that all security decisions be made by the CISO without business input.

    Why it's wrong here

    Effective governance requires collaboration between security and business units. Centralizing all decisions with the CISO can lead to misalignment with business objectives and lack of buy-in. Governance should ensure that security supports the business, which requires input from various stakeholders.

  • ✓

    A clear definition of security roles and responsibilities across the organization.

    Why this is correct

    Clearly defining security roles and responsibilities is essential for accountability and effective governance. It ensures that every aspect of the security program has an owner, preventing gaps and overlaps. This clarity also enables better communication and coordination between business units and the security team, aligning security activities with business goals.

  • ✗

    The implementation of a security operations center (SOC) to monitor for threats 24/7.

    Why it's wrong here

    A SOC is an operational capability, not a governance component. While monitoring is important, governance is about strategic direction and oversight. A SOC may be part of the security program, but it is not essential to the governance framework itself. The framework should define how security is governed, not the specific operational structures.

  • ✓

    A process for regularly reviewing and updating security policies to reflect changes in the threat landscape.

    Why this is correct

    Regular review and updating of security policies is critical to ensure they remain relevant and effective. The threat landscape, business environment, and regulatory requirements evolve, so policies must be dynamic. This process demonstrates proactive governance and helps maintain compliance and risk management over time.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.