CISM Information Security Governance Practice Question
An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?
⚠ Common exam trap
A common mix-up: candidates confuse the policy with lower-level documents like standards or procedures, which are derived from the policy but do not define overall direction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Information security policy
The information security policy is the foundational governance document that articulates the organization's security direction, objectives, and management commitment. It is approved by senior management and mandates the creation of supporting standards, procedures, and guidelines. This aligns with CISM's emphasis on policy as the top-level driver of the security program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Information security standard
Why it's wrong here
Standards are more detailed documents that specify mandatory requirements, such as technical configurations or encryption algorithms, to support the policy. They do not define overall direction and are usually approved at a lower level than senior management, so they do not meet the committee's need.
- ✓
Information security policy
Why this is correct
The information security policy is a high-level document that defines the organization's overall security direction, objectives, and responsibilities. It is typically approved by senior management and serves as the foundation for all other security documents, making it the correct choice for the committee's expectation.
- ✗
Information security procedure
Why it's wrong here
Procedures are step-by-step instructions for carrying out specific tasks and are operational in nature. They do not set overall direction and are not approved by senior management as a governance document, so they are not what the committee should expect.
- ✗
Information security guideline
Why it's wrong here
Guidelines are recommendations or best practices that are not mandatory. They provide advice but do not define the organization's overall security direction or require senior management approval, so they do not fulfill the committee's requirement for a governing document.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.