Courseiva

CISM Information Security Programme Practice Question

A security manager is defining the scope of an information security programme for a fast-growing fintech. Executive sponsors want assurance that the programme will address both organizational and technical dimensions. Which TWO elements are essential components of the programme scope? (Choose two.)

⚠ Common exam trap

The trap here is selecting tangible operational inventories as programme components instead of the governance and risk elements that actually define programme scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defined roles, responsibilities, and accountability for information security across business and technology functions.

Programme scope must cover both governance and risk disciplines. A risk management process translates business context into prioritized protection decisions, while defined roles and accountability ensure those decisions are executed and sustained across functions. Licence lists, marketing plans, and device inventories are useful operational details but are not defining components of programme scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Defined roles, responsibilities, and accountability for information security across business and technology functions.

    Why this is correct

    Clear ownership and accountability are essential because security obligations span business units, engineering, legal, and operations. Assigning responsibility ensures controls are implemented and maintained rather than assumed, enables escalation, and supports the segregation of duties that auditors and regulators expect from a growing fintech.

  • ✗

    A complete inventory of every software licence held by the engineering department.

    Why it's wrong here

    Software licence inventory supports financial and compliance management, but it is an asset management subset rather than a defining component of security programme scope. A licence list does not describe how risk is governed, who is accountable, or how controls are assured, so it cannot serve as an essential programme element.

  • ✗

    A consolidated list of the personal mobile devices used by the sales team.

    Why it's wrong here

    Device inventories feed into asset management and endpoint control, but a list of sales mobile devices is a narrow operational artefact. It does not define how the programme governs risk, assigns responsibility, or assures control effectiveness, so it is not an essential scope element for the overall security programme.

  • ✗

    A marketing plan describing how security certifications will be promoted to prospective customers.

    Why it's wrong here

    Promoting certifications is a commercial activity, not a programme component. While marketable assurance can be a benefit, a marketing plan does not govern risk, define controls, or establish accountability. Including it in programme scope distracts from the operational and governance work needed to actually earn and maintain those certifications.

  • ✓

    A risk management process that identifies, evaluates, and treats information security risk in line with the organization's risk appetite.

    Why this is correct

    Risk management is the core of any security programme because it determines which assets matter, how much protection is justified, and where residual risk must be accepted or transferred. Without an approved risk process tied to appetite, the fintech's controls and spending would be arbitrary and impossible to defend to regulators or the board.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.