Courseiva

CISM Information Security Governance Practice Question

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

⚠ Common exam trap

CISM often tests the distinction between governance (board-level evaluate/direct/monitor activities) and management (operational or reporting-line decisions), so candidates wrongly select structural items like CISO reporting lines or training as if they were oversight mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Board-level risk committee review of security posture

Option C is correct because a board-level risk committee provides structured, recurring oversight by reviewing the organization's security posture against its risk appetite, ensuring cyber risk is governed alongside other enterprise risks. Option D is correct because formal board approval of the information security strategy establishes accountability at the highest level and ensures security objectives are aligned with business goals and adequately resourced. Option E is correct because regular security incident reports give the board timely visibility into material incidents, trends, and remediation status, which is a core mechanism of ongoing board-level oversight. Option A is not essential for board-level oversight, since awareness training educates directors but does not itself create governance or oversight accountability. Option B is also not essential, because while a CISO reporting to the CEO can improve escalation, reporting lines alone do not guarantee board-level oversight of security governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security awareness training for board members

    Why it's wrong here

    Board members need governance artefacts — risk appetite statements, oversight charters and reporting metrics — not instructional content. Awareness training builds individual security knowledge for staff handling data, and would be the right answer where the objective is reducing human error, not establishing board-level accountability.

  • ✗

    CISO reporting directly to the CEO

    Why it's wrong here

    A direct CISO-to-CEO reporting line is an organisational structure choice; board-level oversight requires the board itself to receive security reporting, typically through a board risk committee. It would be correct when clarifying executive escalation paths rather than board governance.

  • ✓

    Board-level risk committee review of security posture

    Why this is correct

    A board-level risk committee provides the governance structure through which directors exercise oversight of security posture, satisfying the stem's requirement for board-level accountability. Unlike operational controls, this mechanism escalates cyber risk into enterprise risk reporting, ensuring strategic decisions and risk tolerance are reviewed at the highest level.

  • ✓

    Approval of the information security strategy by the board

    Why this is correct

    Board approval of the information security strategy directly satisfies the board-level oversight constraint by placing strategic direction, risk appetite and resourcing decisions under directors' formal authority. This governance mechanism ensures accountability sits with the board rather than delegated management, aligning security objectives with organisational strategy and enabling directors to challenge and endorse the approach.

  • ✓

    Regular security incident reports to the board

    Why this is correct

    Regular security incident reports give the board direct visibility of material breaches and control failures, satisfying the oversight requirement for timely, evidence-based assurance. Unlike policy approvals or awareness training, incident reporting provides ongoing operational insight, enabling directors to challenge risk posture and hold management accountable for remediation.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.