CISM Information Security Programme Practice Question
A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)
⚠ Common exam trap
The trap here is equating any security-related activity with governance; governance is about direction, approval, and oversight, not the hands-on execution of controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reviewing and approving the enterprise risk register and accepting residual risks.
Governance involves setting direction, defining risk tolerance, and providing oversight, which includes approving policy and risk appetite and reviewing and accepting residual risks. Operational tasks such as configuring IDS signatures, monitoring dashboards, and running vulnerability scans execute the strategy and controls defined by governance, and are therefore not governance responsibilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reviewing and approving the enterprise risk register and accepting residual risks.
Why this is correct
Reviewing and approving the risk register and formally accepting residual risk are governance responsibilities. They require authority to decide what level of risk the organization will tolerate and to hold risk owners accountable. This oversight ensures that risk decisions are made consistently and at the appropriate level, rather than being delegated to operational teams who implement controls.
- ✓
Approving the information security policy and risk appetite statement.
Why this is correct
Approving policy and risk appetite is a governance function because it sets direction, boundaries, and acceptable risk levels for the organization. It requires authority and accountability at the leadership or board level, not day-to-day operational tasks. This activity ensures the programme operates within agreed parameters and provides the basis for oversight, making it a core governance responsibility.
- ✗
Performing vulnerability scans on internal network segments.
Why it's wrong here
Performing vulnerability scans is a technical, operational task executed by security or IT teams. It involves running tools, analyzing results, and coordinating remediation. While scanning supports risk management, it does not involve setting policy, defining risk appetite, or providing oversight. Therefore, it is an execution activity rather than a governance function.
- ✗
Monitoring security dashboards and triaging alerts on a daily basis.
Why it's wrong here
Daily monitoring and alert triage are operational activities carried out by the security operations center. They involve detecting, analyzing, and responding to events in real time. These tasks execute the strategy and controls defined by governance; they do not establish policy, risk appetite, or oversight. Thus, they fall under execution, not governance.
- ✗
Configuring and tuning intrusion detection system (IDS) signatures.
Why it's wrong here
Configuring and tuning IDS signatures is an operational execution task performed by security operations staff. It involves technical adjustments to detection capabilities based on threat intelligence and environment specifics. While important, it does not set direction or policy and therefore is not a governance responsibility; it is part of the day-to-day execution of the security programme.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.