CISM Information Security Governance Practice Question
An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?
⚠ Common exam trap
CISM often tests the distinction between governance (board-level evaluate/direct/monitor activities) and management (operational or reporting-line decisions), so candidates wrongly select structural items like CISO reporting lines or training as if they were oversight mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Board-level risk committee review of security posture
Option C is correct because a board-level risk committee provides structured, recurring oversight by reviewing the organization's security posture against its risk appetite, ensuring cyber risk is governed alongside other enterprise risks. Option D is correct because formal board approval of the information security strategy establishes accountability at the highest level and ensures security objectives are aligned with business goals and adequately resourced. Option E is correct because regular security incident reports give the board timely visibility into material incidents, trends, and remediation status, which is a core mechanism of ongoing board-level oversight. Option A is not essential for board-level oversight, since awareness training educates directors but does not itself create governance or oversight accountability. Option B is also not essential, because while a CISO reporting to the CEO can improve escalation, reporting lines alone do not guarantee board-level oversight of security governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security awareness training for board members
Why it's wrong here
Board members need governance artefacts — risk appetite statements, oversight charters and reporting metrics — not instructional content. Awareness training builds individual security knowledge for staff handling data, and would be the right answer where the objective is reducing human error, not establishing board-level accountability.
- ✗
CISO reporting directly to the CEO
Why it's wrong here
A direct CISO-to-CEO reporting line is an organisational structure choice; board-level oversight requires the board itself to receive security reporting, typically through a board risk committee. It would be correct when clarifying executive escalation paths rather than board governance.
- ✓
Board-level risk committee review of security posture
Why this is correct
A board-level risk committee provides the governance structure through which directors exercise oversight of security posture, satisfying the stem's requirement for board-level accountability. Unlike operational controls, this mechanism escalates cyber risk into enterprise risk reporting, ensuring strategic decisions and risk tolerance are reviewed at the highest level.
- ✓
Approval of the information security strategy by the board
Why this is correct
Board approval of the information security strategy directly satisfies the board-level oversight constraint by placing strategic direction, risk appetite and resourcing decisions under directors' formal authority. This governance mechanism ensures accountability sits with the board rather than delegated management, aligning security objectives with organisational strategy and enabling directors to challenge and endorse the approach.
- ✓
Regular security incident reports to the board
Why this is correct
Regular security incident reports give the board direct visibility of material breaches and control failures, satisfying the oversight requirement for timely, evidence-based assurance. Unlike policy approvals or awareness training, incident reporting provides ongoing operational insight, enabling directors to challenge risk posture and hold management accountable for remediation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.