hardMultiple Choice
CISM Practice Question: A government agency is criticized for poor…
A government agency is criticized for poor security governance after a data breach. An external review finds that security policies are not aligned with agency's mission. The director wants to implement a governance framework that ties security to strategic objectives. Which framework is most suitable?
⚠ Common exam trap
CISM often tests the distinction between governance and management frameworks, and candidates may incorrectly select ISO 27001 or NIST CSF because they are well-known security standards, but the question specifically asks for a governance framework that ties security to strategic objectives, which is COBIT's primary strength.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
COBIT 2019
COBIT 2019 is specifically designed as an IT governance framework that aligns IT (including security) with enterprise strategic objectives. It provides a comprehensive governance system with principles, enablers, and performance management to ensure that IT delivers value and mitigates risks in line with business goals. Unlike security-focused frameworks, COBIT emphasizes governance and management of enterprise IT, making it ideal for tying security to the agency's mission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NIST Cybersecurity Framework
Why it's wrong here
The NIST Cybersecurity Framework organises outcomes into Identify, Protect, Detect, Respond and Recover functions, but it is voluntary guidance rather than a governance framework binding security to strategic objectives. It tempts because it is government-originated and widely referenced, and suits organisations seeking a common risk vocabulary.
- ✗
PCI DSS
Why it's wrong here
PCI DSS prescribes cardholder-data controls for payment environments, not mission-aligned governance for a government agency. It tempts because it is a recognised security standard with prescriptive requirements, and would be the right choice for an organisation needing to demonstrate compliance when handling payment card data.
- ✓
COBIT 2019
Why this is correct
COBIT 2019 provides a governance and management framework that explicitly links IT and security objectives to enterprise strategy through its governance system design, satisfying the agency's need to align security with mission and strategic objectives rather than only operational controls.
- ✗
ISO 27001
Why it's wrong here
ISO 27001 certifies an information security management system through risk treatment and Annex A controls, but does not map security outcomes to an agency's strategic mission objectives. It tempts because it is a widely adopted governance standard, and would be correct where certification of an ISMS is the stated goal.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.