CISM Information Security Programme Practice Question
An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.
⚠ Common exam trap
Test-takers frequently confuse governance oversight with operational execution, assuming a cross-functional committee should perform hands-on security work.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.
A security steering committee is a governance body whose purpose is to align the security programme with business strategy, approve direction, and prioritize initiatives using cross-functional input. Its membership of business, IT, legal, and risk leaders fits strategic decision-making. Operational execution and independent audit are deliberately separated from this body to preserve both efficiency and objectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform daily monitoring of security alerts and coordinate the response to detected incidents.
Why it's wrong here
Alert monitoring and incident coordination are operational responsibilities handled by the security operations function, not a steering committee. A committee of business, legal, and risk representatives does not meet daily and lacks the technical depth for real-time triage. Assigning operational duties to a governance body would slow response times and blur accountability between oversight and execution roles.
- ✗
Conduct technical vulnerability assessments of critical systems and track remediation activities.
Why it's wrong here
Vulnerability assessment and remediation tracking are execution activities performed by security engineers and system owners. The steering committee's value lies in oversight and prioritization, not hands-on testing. Having the committee run scans would duplicate the security team's work and consume governance time on tactical tasks, leaving strategic issues such as risk appetite and resource allocation unaddressed.
- ✓
Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.
Why this is correct
A security steering committee with cross-functional representation exists to provide governance: setting strategic direction, aligning security investment with business priorities, and resolving conflicts between security and operational needs. This matches its composition, since business, legal, and risk perspectives are needed for strategic trade-off decisions. Operational tasks such as patching or incident response belong to the security team, not this governance body.
- ✗
Independently audit the security programme's controls and report findings directly to external regulators.
Why it's wrong here
Independent audit must be performed by a function outside the programme's governance and management chain to preserve objectivity. A steering committee that helps direct the security programme cannot objectively audit it, and reporting directly to regulators bypasses normal internal reporting structures. Audit independence is a core principle, so this responsibility belongs to internal audit or an external assessor.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.