CISM · domain
Information Security Governance
Practise Certified Information Security Manager CISM Information Security Governance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Information Security Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Information Security Governance
Information Security Governance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Information Security Governance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Information Security Governance questions (85)
Click any question to see the full explanation, or start a practice session above.
Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?
Medium2A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?
Hard3An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?
Hard4During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?
Medium5A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?
Medium6A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?
Hard7Which of the following is the PRIMARY responsibility of the CISO in an organization?
Easy8What is the primary purpose of a security incident near-miss reporting culture?
Easy9Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?
Medium10Which TWO factors are most important when prioritizing security investments? (Select TWO.)
Medium11A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?
Hard12Which component is essential for building a strong security culture within an organization?
Easy13Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?
Easy14A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?
Hard15An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?
Medium16A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?
Medium17An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?
Easy18An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?
Medium19Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?
Easy20Which capability maturity model (CMM) level indicates that security processes are measured and controlled?
Easy21A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?
Hard22Which governance structure is characterized by a single security team that serves the entire organization?
Easy23Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?
Medium24Which of the following is the PRIMARY reason for aligning the information security program with business objectives?
Easy25A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?
Hard26Which of the following is the PRIMARY benefit of having a formal policy exception management process?
Medium27A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)
Medium28An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?
Hard29An organization is developing a security policy for remote access. According to the policy hierarchy, where should this policy fit?
Medium30A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?
Medium31A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?
Hard32A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?
Easy33A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?
Medium34A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?
Hard35An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?
Medium36An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)
Hard37A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?
Hard38An organization is implementing a security culture measurement program. Which THREE metrics would BEST indicate a positive security culture?
Hard39A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?
Hard40Which of the following is the PRIMARY role of the board of directors in information security governance?
Medium41Which of the following is the primary responsibility of the board of directors in information security governance?
Easy42An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?
Medium43A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?
Hard44An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?
Medium45Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?
Easy46Which of the following best describes a key benefit of a centralized information security governance model?
Easy47Which of the following is the BEST example of a board-level security metric?
Easy48Which of the following is the FIRST step in the security policy development lifecycle?
Easy49Which TWO elements are key components of a security culture measurement program?
Easy50A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)
Medium51A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?
Easy52An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?
Medium53An organization is updating its security policies. After drafting the policy, which step should occur NEXT?
Medium54A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?
Hard55Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?
Medium56A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?
Medium57What is the first step in the security policy development lifecycle?
Easy58Which governance model is characterized by a single, centralized security team that serves the entire organization?
Easy59A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?
Hard60A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?
Medium61Which TWO components are essential for an effective information security governance framework?
Easy62Which of the following is the FIRST step in the security policy development lifecycle?
Medium63A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?
Hard64An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?
Medium65During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?
Hard66Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?
Medium67Which board-level committee typically receives security reports to provide oversight?
Medium68In a Capability Maturity Model (CMM) for information security processes, which level is characterized by processes being measured and controlled?
Medium69A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
Medium70Which of the following best describes the role of the chief information security officer (CISO) in a governance context?
Medium71A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?
Medium72The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?
Easy73An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?
Medium74In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?
Medium75A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?
Medium76An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
Medium77An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?
Hard78An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?
Medium79Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?
Medium80A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)
Hard81An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)
Hard82A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?
Medium83An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?
Hard84Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?
Medium85An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?
HardOther domains
All CISM exam domains
Frequently asked questions
- What does the Information Security Governance domain cover on the CISM exam?
- Information Security Governance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 85 Information Security Governance questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Information Security Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.