Courseiva

CISM Information Security Programme Practice Question

A healthcare organization is developing its information security program. The CISO wants to ensure that the program includes appropriate governance components to meet regulatory requirements and manage risk effectively. Which TWO of the following are essential governance components for an information security program? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse operational security capabilities, such as a SOC or penetration testing, with governance components, which are about direction, oversight, and policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A documented information security strategy and supporting policies.

The correct answers are a security steering committee with business unit leaders and a documented information security strategy and supporting policies. These elements provide direction, oversight, and alignment with business goals, which are core to governance. They ensure that security is managed strategically and that accountability is established. Operational capabilities like a SOC or pen testing are important but do not constitute governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A documented information security strategy and supporting policies.

    Why this is correct

    A documented information security strategy and policies are foundational governance components. They provide direction, establish expectations, and define roles and responsibilities. Policies are the basis for enforcing security requirements and demonstrating compliance to regulators. Without them, the program lacks formal authority and consistency. They also enable measurement and accountability, which are critical for governance.

  • ✗

    An annual penetration test conducted by an external vendor.

    Why it's wrong here

    Penetration testing is a technical assessment activity, not a governance component. It provides assurance but does not establish oversight, strategy, or policy. Governance components are structural and directive, such as committees and policies. While pen testing can inform governance decisions, it is not itself a governance mechanism. Thus, it is not an essential governance component.

  • ✗

    A disaster recovery plan that is tested annually.

    Why it's wrong here

    A disaster recovery plan is part of business continuity and operational resilience, not governance. It is a tactical response capability. Governance ensures that such plans exist and are aligned with business objectives, but the plan itself is not a governance component. Therefore, it does not fit the definition of essential governance components for an information security program.

  • ✗

    A real-time security operations center (SOC) with 24/7 monitoring.

    Why it's wrong here

    A SOC is an operational capability, not a governance component. While it is important for detecting and responding to incidents, it does not provide strategic oversight, policy development, or business alignment. Governance focuses on direction and control, whereas a SOC executes those directives. Therefore, it is not an essential governance component, though it may be part of a mature security program.

  • ✓

    A security steering committee that includes business unit leaders.

    Why this is correct

    A security steering committee with business unit representation is a key governance component. It ensures that security decisions are aligned with business needs and that security is integrated into business processes. This committee provides oversight, prioritizes security initiatives, and facilitates communication between security and the business. It also helps in resource allocation and policy approval, making it essential for effective governance.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.