Courseiva

CISM Information Security Programme Practice Question

A newly appointed CISO at a healthcare provider is establishing the information security programme's governance structure. Executive management asks who should ultimately approve the organisation's information security policy. Who is MOST appropriate to approve it?

⚠ Common exam trap

The trap here is assuming the CISO, as programme owner, is also the correct approval authority for the enterprise-wide policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Executive management, because the policy sets enterprise-wide security expectations and demonstrates top-level commitment.

The top-level information security policy sets expectations for the entire organisation and expresses management's risk appetite, so it must be approved by executive management. This provides the authority for enforcement and demonstrates visible commitment. The CISO drafts and maintains it, IT implements it, and internal audit independently assesses compliance against it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The CISO, because they own the information security programme and are accountable for its policies.

    Why it's wrong here

    The CISO drafts, maintains and champions the policy, but approving it alone would remove the visible executive commitment that gives the policy authority across the organisation. Security policy typically imposes obligations on business units outside the CISO's direct control, so approval at a level above the security function is needed for it to be enforceable.

  • ✗

    The internal audit function, because it independently verifies that policy requirements are being met.

    Why it's wrong here

    Internal audit provides independent assurance over the programme and must remain separate from management responsibilities. If audit approved the policy it would later be assessing a document it authored, which compromises the independence that makes audit findings credible. Audit is a reviewer of policy compliance, not the approving authority.

  • ✗

    The IT operations manager, because they implement most of the technical controls described in the policy.

    Why it's wrong here

    IT operations implements controls but has a narrower remit than the whole organisation and no authority over clinical, HR or finance functions. Placing policy approval at that level would create a conflict where the implementing function also sets the requirement, and it would not carry sufficient weight for enterprise-wide compliance.

  • ✓

    Executive management, because the policy sets enterprise-wide security expectations and demonstrates top-level commitment.

    Why this is correct

    Information security policy applies across the whole organisation and must reflect the governing body's risk appetite and direction. Approval by executive management gives the policy the authority needed to compel compliance from every business unit and signals that security is a corporate priority, which is the governance expectation for the top-level policy document.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.