Courseiva

CISM Information Security Programme Practice Question

A security manager is reviewing the organization's security governance framework. The board has requested a clear definition of who is accountable for aligning security strategy with business objectives. According to generally accepted governance principles, which role holds ultimate accountability for the information security program?

⚠ Common exam trap

The trap here is assuming the CISO is accountable because they lead security, when accountability for enterprise risk actually sits with the board.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Board of Directors

Ultimate accountability for the information security program resides with the board of directors, which holds fiduciary duty to stakeholders. The board defines risk appetite and ensures security strategy supports business goals, while the CISO, CIO, and steering committees execute, advise, or coordinate. Distinguishing accountability from responsibility is central to effective governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Chief Information Officer (CIO)

    Why it's wrong here

    The CIO manages information technology operations and infrastructure, and may sponsor security initiatives, but accountability for enterprise security governance rests above the CIO at the board level. The CIO is a management role responsible for delivery, not the fiduciary owner of risk appetite and strategic alignment, which are board-level responsibilities.

  • ✓

    Board of Directors

    Why this is correct

    The board of directors holds fiduciary responsibility to shareholders and is ultimately accountable for enterprise risk, including information security. They set risk appetite, approve strategy, and oversee management. While the CISO executes and the steering committee coordinates, the board owns the accountability for ensuring security aligns with and supports business objectives.

  • ✗

    Chief Information Security Officer (CISO)

    Why it's wrong here

    The CISO is responsible for executing the security strategy and managing day-to-day operations, but accountability for aligning security with business objectives ultimately sits with the board or executive leadership. The CISO advises and implements, yet cannot unilaterally accept enterprise risk on behalf of shareholders, making this role a contributor rather than the accountable authority.

  • ✗

    IT Steering Committee

    Why it's wrong here

    The IT steering committee typically prioritizes projects and allocates IT resources, serving as an advisory and coordination body. It does not carry fiduciary accountability to shareholders, nor does it own enterprise risk. Its role is to recommend and oversee execution, not to be the ultimate accountable party for the security program's alignment with business strategy.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.