easyMultiple Choice
CISM Practice Question: A newly appointed CISO wants to establish an…
A newly appointed CISO wants to establish an information security governance committee. What is the PRIMARY purpose of this committee?
⚠ Common exam trap
A common mix-up: candidates confuse governance (strategic oversight and alignment) with management (tactical implementation and operations), leading them to select options that describe operational or technical tasks rather than the committee's true strategic purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To ensure security strategy aligns with business objectives and provide oversight.
The primary purpose of an information security governance committee is to ensure that the security strategy aligns with business objectives and to provide oversight. This committee does not execute day-to-day operations or implement controls; instead, it sets direction, reviews risk posture, and ensures that security investments support organizational goals, as defined in frameworks like COBIT and ISO 38500.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To manage day-to-day security operations.
Why it's wrong here
Day-to-day operations are handled by security operations staff and line management, not by a governance committee. It is tempting because the committee oversees the security programme, yet its role is strategic alignment and risk oversight, not running operational tasks.
- ✗
To implement security controls across the organization.
Why it's wrong here
Implementing controls is an operational, execution-level task owned by security teams, not a governance body's remit. It is tempting because the committee's decisions do drive control deployment, yet governance sets direction and oversight rather than performing the implementation itself.
- ✗
To approve technical security solutions.
Why it's wrong here
Approving specific technical solutions is a tactical, architecture-level activity, whereas governance operates at strategic direction-setting. It is tempting because the committee does sanction major initiatives, but selecting individual products belongs to technical review boards or change management.
- ✓
To ensure security strategy aligns with business objectives and provide oversight.
Why this is correct
The committee gives the CISO a forum where senior business and security stakeholders agree strategy, prioritise risk, and monitor performance. This ensures security decisions reflect business objectives and receive ongoing executive oversight rather than remaining an isolated technical function.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.