CISM Information Security Governance Practice Question
An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?
⚠ Common exam trap
CISM often tests the misconception that speed or convenience (auto-approval, open request channels) is a control objective, when the exam expects you to recognize that accountability, documentation, and time-bound risk acceptance are the governance essentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approval by the CISO or designated authority
Option A is correct because an exception to a security policy must be authorized by the CISO or another designated authority who owns the risk, ensuring accountability and preventing unauthorized deviations from the baseline. Option C is correct because formal documentation of the exception request captures the justification, scope, risk assessment, compensating controls, and approver, providing an auditable record for compliance and future review. Option E is correct because every exception should carry an expiration date so it is time-bound and automatically reviewed or revoked, preventing permanent, unmanaged risk acceptance. Option B is incorrect because automatic approval after 24 hours of silence would grant exceptions without any risk review or authorization, which is the opposite of effective governance. Option D is incorrect because allowing any employee to request an exception is not itself a critical control; the process must define who is authorized to request and, more importantly, who can approve, so unrestricted requesting does not make the process effective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Approval by the CISO or designated authority
Why this is correct
Requiring approval from the CISO or another designated authority ensures exceptions are granted only by someone holding the risk ownership and authority to accept the residual risk. This satisfies the accountability element, preventing business units from unilaterally bypassing policy.
- ✗
Automatic approval if no response within 24 hours
Why it's wrong here
Silent auto-approval inverts the control: exceptions would be granted by inaction, so unapproved risk bypasses review. It is tempting as a turnaround-time fix, but the process requires explicit, accountable approval by the risk owner; timeouts should escalate or deny, not approve.
- ✓
Formal documentation of the exception request
Why this is correct
Documenting each exception request creates an auditable record of the risk accepted, its justification, scope and approver. This satisfies the traceability element, enabling later review, audit evidence and consistent decisions rather than informal verbal waivers.
- ✗
Ability for any employee to request an exception
Why it's wrong here
Open request rights let anyone raise exceptions, removing the risk-owner gatekeeping that makes the process effective. It is tempting as an accessibility measure, but requests must be routed through the asset or risk owner, with justification and approval, rather than accepted from any employee.
- ✓
An expiration date for the exception
Why this is correct
An expiration date forces periodic re-evaluation of the accepted risk, preventing temporary exceptions from becoming permanent undocumented policy. This satisfies the review element, ensuring the exception is closed or formally renewed once the underlying business justification lapses.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.