Courseiva
Question 230 of 871
Information Security ProgrameasyMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

A multinational organization is establishing an information security program. The Chief Information Security Officer (CISO) wants to ensure the program aligns with business objectives and is accountable to senior management. Which of the following governance structures would best support this goal?

⚠ Common exam trap

Test-takers frequently confuse operational reporting structures (like CISO reporting to CLO or IT ops) with effective governance, overlooking the need for cross-functional management oversight that directly ties security to business objectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An executive steering committee with representatives from business units, legal, and IT meets quarterly to review program status.

An executive steering committee with cross-functional representation (business units, legal, IT) ensures the information security program is aligned with business objectives and provides direct accountability to senior management through regular quarterly reviews. This structure enables strategic oversight, resource allocation, and risk acceptance decisions that tie security initiatives to organizational goals, as recommended by the CISM framework for governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A board-level risk committee oversees the information security program without management involvement.

    Why it's wrong here

    Lack of management representation can hinder operational integration and accountability.

  • An executive steering committee with representatives from business units, legal, and IT meets quarterly to review program status.

    Why this is correct

    This structure ensures alignment, accountability, and cross-functional support.

  • The CISO reports to the chief legal officer (CLO).

    Why it's wrong here

    While legal input is valuable, it may overly emphasize compliance and risk avoidance rather than business enablement.

  • The information security function reports directly to the IT operations manager.

    Why it's wrong here

    Reporting to IT operations can create conflicts and lacks senior management visibility.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.