CISM Information Security Governance Practice Question
A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?
⚠ Common exam trap
The trap here is assuming that centralizing budget control or performing a gap assessment constitutes governance, when governance fundamentally requires a decision-making structure with business representation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an information security steering committee with business unit representation to prioritize and approve security initiatives.
Establishing an information security steering committee is the foundational governance action because it creates a formal, cross-functional body responsible for aligning security investments with enterprise risk appetite. This committee provides the authority and structure to prioritize initiatives, resolve conflicts, and ensure ongoing oversight. Other actions, such as centralizing budgets or conducting assessments, are either tactical or lack the collaborative governance needed to sustain alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an information security steering committee with business unit representation to prioritize and approve security initiatives.
Why this is correct
A steering committee with cross-functional representation establishes formal governance for prioritizing and approving security investments. It directly addresses the lack of central oversight by creating a decision-making body that aligns security spending with enterprise risk appetite. This is a foundational governance step before defining metrics or conducting assessments, as it provides the authority and structure needed for subsequent actions.
- ✗
Develop a security metrics dashboard that reports tool utilization and spending to the board of directors.
Why it's wrong here
A metrics dashboard is a reporting tool that can support governance, but it does not create the governance structure itself. Without a steering committee or clear ownership, the dashboard may simply highlight problems without a mechanism to resolve them. The CISO should first establish the decision-making body that will use the metrics to drive alignment, making this a premature step.
- ✗
Conduct a gap assessment of all existing security tools against the NIST Cybersecurity Framework to identify redundancies.
Why it's wrong here
A gap assessment is valuable for understanding the current state, but it is a tactical analysis rather than a governance action. It does not establish the ongoing oversight and decision-making structure needed to prevent future misalignment. The CISO first needs a governance mechanism to ensure that assessment findings are acted upon and that security investments are strategically directed, not just inventoried.
- ✗
Implement a centralized security budget and require all business units to submit purchase requests to the CISO for approval.
Why it's wrong here
Centralizing the budget may improve control but does not establish a governance framework that aligns security with business strategy. It is an administrative control that could create bottlenecks and lacks the collaborative decision-making needed for effective governance. Without a steering committee, the CISO may lack the authority and business context to prioritize investments appropriately, and this approach may be seen as unilateral.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.