Courseiva

CISM Information Security Programme Practice Question

A security manager is defining the structure of a new information security programme. The CISO has asked for a clear separation of duties between governance and execution. Which TWO of the following activities are typically governance responsibilities rather than operational execution? (Choose two.)

⚠ Common exam trap

The trap here is equating any security-related activity with governance; governance is about direction, approval, and oversight, not the hands-on execution of controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing and approving the enterprise risk register and accepting residual risks.

Governance involves setting direction, defining risk tolerance, and providing oversight, which includes approving policy and risk appetite and reviewing and accepting residual risks. Operational tasks such as configuring IDS signatures, monitoring dashboards, and running vulnerability scans execute the strategy and controls defined by governance, and are therefore not governance responsibilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reviewing and approving the enterprise risk register and accepting residual risks.

    Why this is correct

    Reviewing and approving the risk register and formally accepting residual risk are governance responsibilities. They require authority to decide what level of risk the organization will tolerate and to hold risk owners accountable. This oversight ensures that risk decisions are made consistently and at the appropriate level, rather than being delegated to operational teams who implement controls.

  • ✓

    Approving the information security policy and risk appetite statement.

    Why this is correct

    Approving policy and risk appetite is a governance function because it sets direction, boundaries, and acceptable risk levels for the organization. It requires authority and accountability at the leadership or board level, not day-to-day operational tasks. This activity ensures the programme operates within agreed parameters and provides the basis for oversight, making it a core governance responsibility.

  • ✗

    Performing vulnerability scans on internal network segments.

    Why it's wrong here

    Performing vulnerability scans is a technical, operational task executed by security or IT teams. It involves running tools, analyzing results, and coordinating remediation. While scanning supports risk management, it does not involve setting policy, defining risk appetite, or providing oversight. Therefore, it is an execution activity rather than a governance function.

  • ✗

    Monitoring security dashboards and triaging alerts on a daily basis.

    Why it's wrong here

    Daily monitoring and alert triage are operational activities carried out by the security operations center. They involve detecting, analyzing, and responding to events in real time. These tasks execute the strategy and controls defined by governance; they do not establish policy, risk appetite, or oversight. Thus, they fall under execution, not governance.

  • ✗

    Configuring and tuning intrusion detection system (IDS) signatures.

    Why it's wrong here

    Configuring and tuning IDS signatures is an operational execution task performed by security operations staff. It involves technical adjustments to detection capabilities based on threat intelligence and environment specifics. While important, it does not set direction or policy and therefore is not a governance responsibility; it is part of the day-to-day execution of the security programme.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.