CISM Information Security Governance Practice Question
A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?
⚠ Common exam trap
CISM often tests the difference between administrative requirements (documentation, approval, expiration) and risk mitigation (compensating controls). Candidates may choose documentation or approval as most important, but the key is that compensating controls address the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementation of compensating controls
The most important requirement for a policy exception is the implementation of compensating controls. While documentation, approval, and expiration are important, compensating controls ensure that the risk introduced by the exception is mitigated to an acceptable level. Without compensating controls, the exception could expose the organization to unacceptable risk, undermining the purpose of the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Documentation of the exception
Why it's wrong here
Documentation records the deviation but does not itself authorise it; an exception requires approval by the appropriate risk owner. It is tempting because auditability matters, yet unapproved documentation leaves the risk formally unaccepted, which is the process's central requirement.
- ✓
Implementation of compensating controls
Why this is correct
Compensating controls reduce the residual risk the policy deviation introduces, keeping exposure within the organisation's risk appetite for the exception's duration. Without them, the exception would leave the identified risk entirely unmitigated, which governance cannot accept.
- ✗
Approval by the CISO only
Why it's wrong here
CISO-only approval bypasses the business or system owner who owns the risk and its compensating controls. It is tempting because centralised security sign-off appears rigorous, but exceptions require the accountable risk owner's acceptance, with the CISO advising rather than sole approver.
- ✗
A fixed expiration date
Why it's wrong here
A fixed expiration date bounds the deviation, but without documented risk acceptance and approval the exception is unmanaged. It is tempting because time-boxing prevents permanent drift, yet the process's core control is recorded justification and authorisation, making expiry a secondary attribute.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.