Courseiva

CISM Information Security Programme Practice Question

A newly appointed CISO is formalizing the information security programme charter. The CIO asks which element MUST be documented in the charter to enable the CISO to enforce policy across business units that do not report to the CIO. Which element is MOST important to include?

⚠ Common exam trap

The trap here is treating the charter as a technical or compliance inventory rather than the governance instrument that grants the security function its authority and scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A statement of the security programme's authority, scope, and mandate approved by executive leadership

A programme charter derives its force from executive endorsement of the security function's authority, scope, and mandate. That endorsement is what lets the CISO issue binding policy to business units beyond their own reporting line. Operational inventories, regulatory texts, and product roadmaps are supporting artifacts that change often and carry no governance authority, so they cannot resolve the enforcement question the CIO raised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The full text of every regulatory requirement the organization must satisfy

    Why it's wrong here

    Regulatory obligations belong in a compliance register or obligation-mapping document that evolves continuously. Embedding them in the charter would make a governance document brittle and force re-approval at the executive level every time a regulation changes. It also does not answer how the CISO gains enforcement authority over non-reporting business units.

  • ✓

    A statement of the security programme's authority, scope, and mandate approved by executive leadership

    Why this is correct

    The charter's authority statement, endorsed at the executive level, gives the CISO the delegated power to set and enforce policy across units outside the CIO's chain of command. Without that explicit mandate, enforcement relies on persuasion rather than governance authority, and business units can legitimately claim the security function has no jurisdiction over them.

  • ✗

    A detailed inventory of every security tool currently deployed across the enterprise

    Why it's wrong here

    A tool inventory is an operational asset-management artifact, not a governance instrument. It describes what exists today but confers no authority, defines no scope, and cannot compel an unwilling business unit to comply. Including it in the charter adds maintenance burden without addressing the CIO's actual question of how the CISO can enforce policy outside their reporting line.

  • ✗

    A three-year roadmap listing specific security products planned for procurement

    Why it's wrong here

    A procurement roadmap is a planning artifact subordinate to strategy, and it changes frequently as threats and budgets shift. Approving product plans as charter content would conflate governance with tactical purchasing, and it provides no delegated authority for the CISO to direct business units that sit outside the CIO's reporting structure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.