CISM Information Security Programme Practice Question
A security manager is reviewing the organization's security governance framework. The board of directors has asked for assurance that security risks are being managed effectively. Which of the following is the MOST important element to include in the governance framework?
⚠ Common exam trap
Candidates often confuse operational artifacts, such as tool lists or testing schedules, with governance elements that provide strategic oversight and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A clear definition of security roles and responsibilities.
Effective security governance requires clear definition of roles and responsibilities to establish accountability and oversight. This enables the board to have assurance that security risks are managed. Other elements like tools, diagrams, and testing schedules are operational and do not fulfill governance needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all security tools deployed in the environment.
Why it's wrong here
A list of tools is an inventory, not a governance element. Governance focuses on direction, oversight, and accountability, not on specific technologies. While tools support security, they do not provide assurance to the board about risk management effectiveness without proper governance structures.
- ✗
A detailed technical security architecture diagram.
Why it's wrong here
A technical architecture diagram is useful for implementation but does not constitute governance. Governance requires policies, roles, and processes that ensure security aligns with business objectives. The board needs assurance that risks are managed, not technical details, which are more operational.
- ✓
A clear definition of security roles and responsibilities.
Why this is correct
Clear roles and responsibilities ensure accountability and are fundamental to effective governance. They define who is responsible for what, enabling oversight and decision-making. This is essential for the board to have assurance that security risks are managed, as it establishes ownership and reporting lines.
- ✗
A schedule for penetration testing.
Why it's wrong here
Penetration testing is a control activity, not a governance element. While it provides assurance on specific technical controls, it does not address overall risk management, accountability, or strategic alignment. Governance frameworks should include oversight mechanisms, not just testing schedules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.