Courseiva
hardMultiple Choice

CISM Practice Question: A government agency is criticized for poor…

A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?

⚠ Common exam trap

CISM often tests the distinction between governance and management frameworks, and candidates may incorrectly select ISO 27001 or NIST CSF because they are well-known security standards, but the question specifically asks for a governance framework that ties security to strategic objectives, which is COBIT's primary strength.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

COBIT 2019

COBIT 2019 is specifically designed as an IT governance framework that aligns IT (including security) with enterprise strategic objectives. It provides a comprehensive governance system with principles, enablers, and performance management to ensure that IT delivers value and mitigates risks in line with business goals. Unlike security-focused frameworks, COBIT emphasizes governance and management of enterprise IT, making it ideal for tying security to the agency's mission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NIST Cybersecurity Framework

    Why it's wrong here

    The NIST Cybersecurity Framework organises outcomes into Identify, Protect, Detect, Respond and Recover functions, but it is voluntary guidance rather than a governance framework binding security to strategic objectives. It tempts because it is government-originated and widely referenced, and suits organisations seeking a common risk vocabulary.

  • ✗

    PCI DSS

    Why it's wrong here

    PCI DSS prescribes cardholder-data controls for payment environments, not mission-aligned governance for a government agency. It tempts because it is a recognised security standard with prescriptive requirements, and would be the right choice for an organisation needing to demonstrate compliance when handling payment card data.

  • ✓

    COBIT 2019

    Why this is correct

    COBIT 2019 provides a governance and management framework that explicitly links IT and security objectives to enterprise strategy through its governance system design, satisfying the agency's need to align security with mission and strategic objectives rather than only operational controls.

  • ✗

    ISO 27001

    Why it's wrong here

    ISO 27001 certifies an information security management system through risk treatment and Annex A controls, but does not map security outcomes to an agency's strategic mission objectives. It tempts because it is a widely adopted governance standard, and would be correct where certification of an ISMS is the stated goal.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.