Courseiva

CISM Information Security Governance Practice Question

An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?

⚠ Common exam trap

A common mix-up: candidates confuse the policy with lower-level documents like standards or procedures, which are derived from the policy but do not define overall direction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Information security policy

The information security policy is the foundational governance document that articulates the organization's security direction, objectives, and management commitment. It is approved by senior management and mandates the creation of supporting standards, procedures, and guidelines. This aligns with CISM's emphasis on policy as the top-level driver of the security program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Information security standard

    Why it's wrong here

    Standards are more detailed documents that specify mandatory requirements, such as technical configurations or encryption algorithms, to support the policy. They do not define overall direction and are usually approved at a lower level than senior management, so they do not meet the committee's need.

  • ✓

    Information security policy

    Why this is correct

    The information security policy is a high-level document that defines the organization's overall security direction, objectives, and responsibilities. It is typically approved by senior management and serves as the foundation for all other security documents, making it the correct choice for the committee's expectation.

  • ✗

    Information security procedure

    Why it's wrong here

    Procedures are step-by-step instructions for carrying out specific tasks and are operational in nature. They do not set overall direction and are not approved by senior management as a governance document, so they are not what the committee should expect.

  • ✗

    Information security guideline

    Why it's wrong here

    Guidelines are recommendations or best practices that are not mandatory. They provide advice but do not define the organization's overall security direction or require senior management approval, so they do not fulfill the committee's requirement for a governing document.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.