Courseiva

CISM · domain

Information Security Governance

Domain 1 of the CISM exam covers establishing and maintaining an information security governance framework that aligns security strategy with business objectives. Questions test governance structures, roles and reporting lines, regulatory and legal drivers, policy hierarchy, risk appetite, metrics reported to the board, and how security culture and third-party relationships are governed and measured.

108 questions25 easy48 medium35 hard

Focused practice

Practice Information Security Governance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Security Governance

Be able to align security governance with business strategy, assign accountability correctly, and pick metrics the board can act on. The single most important thing: prioritize and decide based on business risk and regulatory obligation, not on technology preference or security team convenience.

Aligning security strategy and roadmap priorities with business objectives, risk appetite, and regulatory obligations

Assigning governance accountability across the board, steering committee, CISO, and business process owners

Applying policy hierarchy: enterprise policy, standards, baselines, procedures, and guidelines

Selecting board-level metrics such as incident response effectiveness, control coverage, and culture indicators

Watch out for

Common Information Security Governance exam traps

  • ▸Treating technology tools or vendor products as the primary driver of roadmap priorities instead of business risk and strategy
  • ▸Assuming the CISO or security team owns all risk, rather than business process owners accepting and owning risk
  • ▸Choosing operational metrics like patch counts or alert volumes when the question asks for board-level governance metrics

Question index

All Information Security Governance questions (108)

Click any question to see the full explanation, or start a practice session above.

1

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

Medium
2

A CISO is reviewing the information security strategy and needs to ensure that security investments are justified in business terms. The CFO has requested that each security initiative be tied to a financial metric that reflects potential loss from cyber events. Which approach is MOST appropriate for the CISO to use?

Medium
3

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

Hard
4

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Hard
5

A healthcare organization is developing its information security strategy. The CISO is considering how to best align the strategy with the organization's overall business strategy. Which of the following approaches would be MOST effective?

Medium
6

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

Medium
7

Which of the following is the PRIMARY responsibility of the CISO in an organization?

Easy
8

What is the primary purpose of a security incident near-miss reporting culture?

Easy
9

A newly appointed CISO is establishing an information security governance framework. The organization has a complex structure with multiple business units, each with its own IT function. The CISO wants to ensure that security decisions are made with input from all relevant stakeholders and that security risks are managed consistently across the enterprise. Which of the following should be the CISO's FIRST step in establishing this framework?

Medium
10

Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?

Medium
11

Which TWO factors are most important when prioritizing security investments? (Select TWO.)

Medium
12

A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?

Hard
13

Which component is essential for building a strong security culture within an organization?

Easy
14

Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?

Easy
15

A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?

Hard
16

An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?

Medium
17

A financial services company has a policy requiring annual risk assessments for all critical vendors. During an internal audit, it is discovered that several vendors have not been reassessed in over two years. The CISO needs to address this governance gap. Which action should be taken FIRST?

Medium
18

A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)

Hard
19

A CISO is presenting the information security program's value to the board. The board is particularly concerned about the organization's ability to detect and respond to advanced threats. Which of the following metrics would BEST demonstrate the program's effectiveness in this area?

Medium
20

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

Easy
21

An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?

Medium
22

A global financial services firm is establishing an information security governance framework. The board of directors wants assurance that security risks are managed effectively across all business units. Which of the following is the MOST important element for the CISO to implement to provide this assurance?

Medium
23

A multinational corporation operates in multiple jurisdictions with varying data protection laws. The CISO is establishing a governance structure to manage compliance with these laws while maintaining a consistent security posture. Which of the following is the MOST effective approach for the CISO to take?

Hard
24

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that the framework will effectively manage risk and comply with regulations such as GDPR and PCI DSS. Which of the following are essential components of an effective information security governance framework? (Choose two.)

Hard
25

Which capability maturity model (CMM) level indicates that security processes are measured and controlled?

Easy
26

A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?

Hard
27

A security manager is reviewing the organization's information security governance framework. The board has expressed concern that security decisions are not consistently aligned with the organization's risk appetite. Which of the following would BEST address this concern?

Hard
28

Which governance structure is characterized by a single security team that serves the entire organization?

Easy
29

Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?

Medium
30

A CISO is reviewing the organization's risk management process. The board has asked how the CISO ensures that security risks are managed within the organization's risk appetite. Which activity BEST demonstrates this?

Hard
31

A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?

Hard
32

A global retailer is establishing an information security governance framework. The CISO must ensure that the framework addresses both internal and external requirements. Which THREE of the following are essential components of an effective information security governance framework? (Choose three.)

Hard
33

Which of the following is the PRIMARY benefit of having a formal policy exception management process?

Medium
34

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

Medium
35

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

Hard
36

An organization's security steering committee is reviewing the information security policy framework. The committee wants to ensure that the framework includes a document that defines the organization's overall security direction and is approved by senior management. Which document should the committee expect to find?

Easy
37

A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?

Medium
38

A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?

Hard
39

A CISO is designing a security governance framework for a multinational corporation. The framework must address the need for clear accountability, alignment with business strategy, and effective risk management across diverse business units. Which TWO of the following are essential components of such a governance framework? (Choose two.)

Hard
40

A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?

Easy
41

A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?

Medium
42

A CISO is developing a set of information security policies for a healthcare organization. The organization must comply with HIPAA and internal privacy requirements. Which of the following should be the PRIMARY consideration when drafting the security policy framework?

Easy
43

A security manager is developing key performance indicators (KPIs) for the information security program. Which of the following is the MOST important characteristic of an effective KPI?

Easy
44

A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?

Hard
45

An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?

Medium
46

An organization's information security strategy is being developed. The CISO wants to ensure that the strategy supports business objectives while managing risk. Which of the following should be the PRIMARY input to the strategy development process?

Easy
47

A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?

Hard
48

An organization has recently experienced a data breach that resulted in the loss of customer personally identifiable information (PII). The board of directors is concerned about the effectiveness of the information security governance program. Which of the following should the CISO recommend as the MOST important action to improve governance?

Easy
49

A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?

Hard
50

Which of the following is the primary responsibility of the board of directors in information security governance?

Easy
51

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

Medium
52

A financial services company is updating its information security policies to reflect a new regulation. The CISO must ensure the policies are effectively communicated and enforced. Which action is MOST important to achieve this?

Medium
53

A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?

Hard
54

An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?

Medium
55

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

Easy
56

Which of the following best describes a key benefit of a centralized information security governance model?

Easy
57

Which of the following is the BEST example of a board-level security metric?

Easy
58

A CISO is developing a set of metrics to report to the board on the effectiveness of the information security governance program. Which of the following metrics would BEST demonstrate that security governance is aligned with business objectives? (Choose two.)

Hard
59

Which TWO elements are key components of a security culture measurement program?

Easy
60

A global financial services firm is aligning its information security program with the COBIT framework. The board wants assurance that IT risks are governed effectively. Which COBIT component is MOST directly responsible for ensuring that IT risk management activities are aligned with enterprise risk management?

Hard
61

A CISO is establishing an information security governance framework for a financial services firm. The board has asked for assurance that security risks are managed effectively and that the program aligns with regulatory requirements. Which TWO elements are MOST critical for the CISO to define as part of this governance framework? (Choose two.)

Medium
62

A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)

Medium
63

A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?

Easy
64

An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?

Medium
65

A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?

Hard
66

Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?

Medium
67

A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?

Medium
68

An organization's information security strategy is being updated to align with the business goal of expanding into new markets. The CISO must ensure that the strategy addresses the varying legal and regulatory requirements of these markets. Which of the following should be the PRIMARY consideration when updating the strategy?

Hard
69

A CISO is updating the organization's information security policy to reflect a new regulatory requirement. The policy must be approved before it can be communicated to employees. Who is MOST appropriate to approve the updated policy?

Easy
70

Which governance model is characterized by a single, centralized security team that serves the entire organization?

Easy
71

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

Hard
72

A CISO is updating the enterprise information security strategy. The organization's business strategy now emphasizes rapid expansion into cloud-based services and third-party partnerships. Which of the following should be the CISO's FIRST action to ensure the security strategy remains aligned with the business strategy?

Medium
73

Which TWO components are essential for an effective information security governance framework?

Easy
74

A global financial services firm is revising its information security governance framework. The board of directors has expressed concern that the current security strategy is not adequately aligned with the firm's business objectives and regulatory obligations. The CISO is tasked with improving this alignment. Which of the following actions would BEST address the board's concern?

Hard
75

Which of the following is the FIRST step in the security policy development lifecycle?

Medium
76

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

Hard
77

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

Medium
78

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

Hard
79

A global retailer is expanding into new markets and must comply with varying data protection laws. The CISO is revising the information security strategy to ensure it remains aligned with the changing business environment. Which approach BEST ensures ongoing alignment between the security strategy and business objectives?

Hard
80

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

Medium
81

Which board-level committee typically receives security reports to provide oversight?

Medium
82

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

Medium
83

A newly appointed CISO at a healthcare payer discovers that business units independently purchase security tools, resulting in overlapping capabilities and no central oversight. The CISO wants to establish a governance structure that ensures security investments align with enterprise risk appetite. Which action should the CISO take FIRST?

Medium
84

A CISO is developing a set of key risk indicators (KRIs) to monitor information security governance effectiveness. The CISO wants to ensure that the KRIs are actionable and aligned with business objectives. Which two characteristics are MOST important for effective KRIs? (Choose two.)

Hard
85

Which of the following best describes the role of the chief information security officer (CISO) in a governance context?

Medium
86

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Medium
87

The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?

Easy
88

A CISO is updating the organization's information security strategy to address emerging risks from cloud adoption and remote work. Which of the following should be the FIRST step in this process?

Medium
89

An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?

Medium
90

A global retailer's CISO is establishing an information security governance framework. The company operates in 20 countries, each with different privacy laws. The board wants assurance that security investments are justified and risks are managed consistently. Which governance mechanism BEST provides this assurance?

Hard
91

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

Medium
92

A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?

Medium
93

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

Medium
94

A healthcare organization is developing an information security governance framework. The CISO needs to ensure that the framework supports regulatory compliance with HIPAA and aligns with the organization's strategic goals. Which of the following should be the FIRST step in this process?

Medium
95

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

Hard
96

An organization has recently experienced a data breach that resulted in reputational damage and regulatory fines. The board has asked the CISO to improve the information security governance framework to prevent future incidents. Which of the following should the CISO do FIRST?

Easy
97

An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?

Medium
98

A financial services firm with a federated governance model is revising its information security strategy. The board has mandated that security investments must demonstrably support business objectives. The CISO is asked to define the MOST effective way to align security governance with business strategy. Which of the following should the CISO do FIRST?

Medium
99

An organization is updating its information security policy framework. The CISO wants to ensure that the policies are effectively communicated and understood by all employees. Which of the following is the MOST effective method to achieve this?

Medium
100

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

Medium
101

A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)

Hard
102

An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)

Hard
103

A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?

Medium
104

An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?

Hard
105

A CISO at a healthcare insurer is revising the information security strategy after a merger with a smaller regional provider. The board has asked how security will support the combined company's growth targets while protecting patient data. Which action BEST aligns the security strategy with the business objectives?

Medium
106

Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?

Medium
107

A newly appointed CISO is reviewing the organization's information security governance framework. The CISO finds that security responsibilities are not clearly defined across business units, leading to gaps and overlaps. Which of the following should the CISO do FIRST to address this issue?

Easy
108

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Hard

Frequently asked questions

What does the Information Security Governance domain cover on the CISM exam?
Be able to align security governance with business strategy, assign accountability correctly, and pick metrics the board can act on. The single most important thing: prioritize and decide based on business risk and regulatory obligation, not on technology preference or security team convenience.
How many questions are in this domain?
This page lists all 108 Information Security Governance questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Security Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism governance Practice Questions