CISM Information Security Governance Practice Question
An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?
⚠ Common exam trap
CISM often tests the distinction between tactical security measures and strategic cultural drivers; candidates may choose a visible, hands-on option like phishing simulations or training budgets, overlooking that executive sponsorship is the foundational element that enables all other initiatives to succeed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establishing executive sponsorship of security
Establishing executive sponsorship of security directly addresses the root of security culture: leadership commitment. When executives visibly champion security, it signals to the entire organization that security is a core value, not just a compliance checkbox. This top-down influence shapes employee attitudes and behaviors more effectively than any single tactical initiative. Executive sponsorship also ensures that security is integrated into business decisions and receives necessary resources, creating a sustainable culture change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increasing the security awareness training budget
Why it's wrong here
Budget alone funds content delivery without altering board behaviour, incentives or reporting norms, so it does not shift shared beliefs. It is tempting because awareness training is the visible, measurable control boards already approve, and would be correct where the gap is staff knowledge of phishing or policy rather than culture itself.
- ✗
Implementing a near-miss reporting system
Why it's wrong here
Near-miss reporting surfaces incidents but does not by itself change executive behaviour, incentives or the tone set at board level, which drive culture. It is tempting because reporting systems are a recognised culture metric, and would be correct where the organisation already has psychological safety and simply lacks data on emerging threats.
- ✓
Establishing executive sponsorship of security
Why this is correct
Executive sponsorship signals that security is a business priority, driving resource allocation, accountability and behavioural change across the organisation. Board-level backing shapes culture far more than awareness campaigns or technical controls, satisfying the stem's demand for the greatest cultural impact.
- ✗
Conducting monthly phishing simulations
Why it's wrong here
Simulations measure and reinforce individual click behaviour but leave board governance, incentives and leadership modelling untouched, which shape culture. It is tempting because phishing metrics are quantifiable and easy to report, and would be correct where the specific objective is reducing susceptibility to credential-harvesting emails rather than culture change.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.