Courseiva

CISM Information Security Governance Practice Question

An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?

⚠ Common exam trap

CISM often tests the distinction between tactical security measures and strategic cultural drivers; candidates may choose a visible, hands-on option like phishing simulations or training budgets, overlooking that executive sponsorship is the foundational element that enables all other initiatives to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishing executive sponsorship of security

Establishing executive sponsorship of security directly addresses the root of security culture: leadership commitment. When executives visibly champion security, it signals to the entire organization that security is a core value, not just a compliance checkbox. This top-down influence shapes employee attitudes and behaviors more effectively than any single tactical initiative. Executive sponsorship also ensures that security is integrated into business decisions and receives necessary resources, creating a sustainable culture change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increasing the security awareness training budget

    Why it's wrong here

    Budget alone funds content delivery without altering board behaviour, incentives or reporting norms, so it does not shift shared beliefs. It is tempting because awareness training is the visible, measurable control boards already approve, and would be correct where the gap is staff knowledge of phishing or policy rather than culture itself.

  • ✗

    Implementing a near-miss reporting system

    Why it's wrong here

    Near-miss reporting surfaces incidents but does not by itself change executive behaviour, incentives or the tone set at board level, which drive culture. It is tempting because reporting systems are a recognised culture metric, and would be correct where the organisation already has psychological safety and simply lacks data on emerging threats.

  • ✓

    Establishing executive sponsorship of security

    Why this is correct

    Executive sponsorship signals that security is a business priority, driving resource allocation, accountability and behavioural change across the organisation. Board-level backing shapes culture far more than awareness campaigns or technical controls, satisfying the stem's demand for the greatest cultural impact.

  • ✗

    Conducting monthly phishing simulations

    Why it's wrong here

    Simulations measure and reinforce individual click behaviour but leave board governance, incentives and leadership modelling untouched, which shape culture. It is tempting because phishing metrics are quantifiable and easy to report, and would be correct where the specific objective is reducing susceptibility to credential-harvesting emails rather than culture change.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.