Courseiva

CISM Information Security Governance Practice Question

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

⚠ Common exam trap

CISM often tests the misconception that speed or convenience (auto-approval, open request channels) is a control objective, when the exam expects you to recognize that accountability, documentation, and time-bound risk acceptance are the governance essentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approval by the CISO or designated authority

Option A is correct because an exception to a security policy must be authorized by the CISO or another designated authority who owns the risk, ensuring accountability and preventing unauthorized deviations from the baseline. Option C is correct because formal documentation of the exception request captures the justification, scope, risk assessment, compensating controls, and approver, providing an auditable record for compliance and future review. Option E is correct because every exception should carry an expiration date so it is time-bound and automatically reviewed or revoked, preventing permanent, unmanaged risk acceptance. Option B is incorrect because automatic approval after 24 hours of silence would grant exceptions without any risk review or authorization, which is the opposite of effective governance. Option D is incorrect because allowing any employee to request an exception is not itself a critical control; the process must define who is authorized to request and, more importantly, who can approve, so unrestricted requesting does not make the process effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Approval by the CISO or designated authority

    Why this is correct

    Requiring approval from the CISO or another designated authority ensures exceptions are granted only by someone holding the risk ownership and authority to accept the residual risk. This satisfies the accountability element, preventing business units from unilaterally bypassing policy.

  • ✗

    Automatic approval if no response within 24 hours

    Why it's wrong here

    Silent auto-approval inverts the control: exceptions would be granted by inaction, so unapproved risk bypasses review. It is tempting as a turnaround-time fix, but the process requires explicit, accountable approval by the risk owner; timeouts should escalate or deny, not approve.

  • ✓

    Formal documentation of the exception request

    Why this is correct

    Documenting each exception request creates an auditable record of the risk accepted, its justification, scope and approver. This satisfies the traceability element, enabling later review, audit evidence and consistent decisions rather than informal verbal waivers.

  • ✗

    Ability for any employee to request an exception

    Why it's wrong here

    Open request rights let anyone raise exceptions, removing the risk-owner gatekeeping that makes the process effective. It is tempting as an accessibility measure, but requests must be routed through the asset or risk owner, with justification and approval, rather than accepted from any employee.

  • ✓

    An expiration date for the exception

    Why this is correct

    An expiration date forces periodic re-evaluation of the accepted risk, preventing temporary exceptions from becoming permanent undocumented policy. This satisfies the review element, ensuring the exception is closed or formally renewed once the underlying business justification lapses.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.