CISM Information Security Programme Practice Question
A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?
⚠ Common exam trap
The trap here is treating the charter as a technical or compliance inventory rather than the governance instrument that grants the security function its authority and scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A statement of the security programme's authority, scope, and mandate approved by executive leadership
A programme charter derives its force from executive endorsement of the security function's authority, scope, and mandate. That endorsement is what lets the CISO issue binding policy to business units beyond their own reporting line. Operational inventories, regulatory texts, and product roadmaps are supporting artifacts that change often and carry no governance authority, so they cannot resolve the enforcement question the CIO raised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The full text of every regulatory requirement the organization must satisfy
Why it's wrong here
Regulatory obligations belong in a compliance register or obligation-mapping document that evolves continuously. Embedding them in the charter would make a governance document brittle and force re-approval at the executive level every time a regulation changes. It also does not answer how the CISO gains enforcement authority over non-reporting business units.
- ✓
A statement of the security programme's authority, scope, and mandate approved by executive leadership
Why this is correct
The charter's authority statement, endorsed at the executive level, gives the CISO the delegated power to set and enforce policy across units outside the CIO's chain of command. Without that explicit mandate, enforcement relies on persuasion rather than governance authority, and business units can legitimately claim the security function has no jurisdiction over them.
- ✗
A detailed inventory of every security tool currently deployed across the enterprise
Why it's wrong here
A tool inventory is an operational asset-management artifact, not a governance instrument. It describes what exists today but confers no authority, defines no scope, and cannot compel an unwilling business unit to comply. Including it in the charter adds maintenance burden without addressing the CIO's actual question of how the CISO can enforce policy outside their reporting line.
- ✗
A three-year roadmap listing specific security products planned for procurement
Why it's wrong here
A procurement roadmap is a planning artifact subordinate to strategy, and it changes frequently as threats and budgets shift. Approving product plans as charter content would conflate governance with tactical purchasing, and it provides no delegated authority for the CISO to direct business units that sit outside the CIO's reporting structure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.