Courseiva

CISM Information Security Programme Practice Question

An organization's security steering committee includes representatives from business units, IT, legal, and risk management. The CISO must decide which function this committee should perform within the information security programme.

⚠ Common exam trap

Test-takers frequently confuse governance oversight with operational execution, assuming a cross-functional committee should perform hands-on security work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.

A security steering committee is a governance body whose purpose is to align the security programme with business strategy, approve direction, and prioritize initiatives using cross-functional input. Its membership of business, IT, legal, and risk leaders fits strategic decision-making. Operational execution and independent audit are deliberately separated from this body to preserve both efficiency and objectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform daily monitoring of security alerts and coordinate the response to detected incidents.

    Why it's wrong here

    Alert monitoring and incident coordination are operational responsibilities handled by the security operations function, not a steering committee. A committee of business, legal, and risk representatives does not meet daily and lacks the technical depth for real-time triage. Assigning operational duties to a governance body would slow response times and blur accountability between oversight and execution roles.

  • ✗

    Conduct technical vulnerability assessments of critical systems and track remediation activities.

    Why it's wrong here

    Vulnerability assessment and remediation tracking are execution activities performed by security engineers and system owners. The steering committee's value lies in oversight and prioritization, not hands-on testing. Having the committee run scans would duplicate the security team's work and consume governance time on tactical tasks, leaving strategic issues such as risk appetite and resource allocation unaddressed.

  • ✓

    Approve the strategic direction of the security programme and prioritize security initiatives against business objectives.

    Why this is correct

    A security steering committee with cross-functional representation exists to provide governance: setting strategic direction, aligning security investment with business priorities, and resolving conflicts between security and operational needs. This matches its composition, since business, legal, and risk perspectives are needed for strategic trade-off decisions. Operational tasks such as patching or incident response belong to the security team, not this governance body.

  • ✗

    Independently audit the security programme's controls and report findings directly to external regulators.

    Why it's wrong here

    Independent audit must be performed by a function outside the programme's governance and management chain to preserve objectivity. A steering committee that helps direct the security programme cannot objectively audit it, and reporting directly to regulators bypasses normal internal reporting structures. Audit independence is a core principle, so this responsibility belongs to internal audit or an external assessor.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.