CISM Information Security Governance Practice Question
A newly appointed CISO is establishing an information security governance framework. The organization has a complex structure with multiple business units, each with its own IT function. The CISO wants to ensure that security decisions are made with input from all relevant stakeholders and that security risks are managed consistently across the enterprise. Which of the following should be the CISO's FIRST step in establishing this framework?
⚠ Common exam trap
The trap here is assuming that a technical activity like risk assessment or policy writing must come first, when governance actually begins with establishing decision-making structures and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security steering committee composed of senior leaders from each business unit and key corporate functions.
Establishing a security steering committee is the foundational step for governance because it creates the decision-making body that aligns security with business strategy, ensures cross-functional representation, and provides oversight for risk management. Without this structure, subsequent activities like risk assessment, policy development, and awareness training may lack coordination and strategic alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a security awareness training program for all employees to build a security culture.
Why it's wrong here
Awareness training is a valuable component of a security program, but it is not the first step in establishing governance. Governance requires structure and oversight before launching programs. The CISO must first establish the steering committee to provide direction, approve initiatives, and ensure resources are allocated appropriately. Training without governance may be unfocused and less effective.
- ✗
Conduct a comprehensive security risk assessment to identify all vulnerabilities and threats.
Why it's wrong here
While risk assessment is important, it is not the first step in establishing governance. Governance is about decision-making structures and accountability. Without a steering committee or similar body, the risk assessment may lack the necessary oversight and may not be aligned with business strategy. The CISO should first establish the governance framework to guide subsequent risk activities.
- ✓
Create a security steering committee composed of senior leaders from each business unit and key corporate functions.
Why this is correct
A security steering committee provides a governance structure for cross-functional decision-making and consistent risk management. It ensures that security is aligned with business objectives and that all stakeholders have a voice. This is a foundational step in establishing governance because it creates the mechanism for oversight and direction, enabling the CISO to drive policy, risk appetite, and resource allocation across the enterprise.
- ✗
Develop a detailed information security policy manual that mandates compliance from all business units.
Why it's wrong here
Policies are essential but should be developed under the governance framework. Writing policies first without governance can lead to lack of buy-in and misalignment with business needs. The steering committee should oversee policy development to ensure it reflects the organization's risk appetite and business objectives. Thus, policy creation is not the initial step.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.