Courseiva

CISM · domain

Information Security Governance

Practise Certified Information Security Manager CISM Information Security Governance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

85 questions21 easy40 medium24 hard

Focused practice

Practice Information Security Governance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Security Governance

Information Security Governance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Information Security Governance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Information Security Governance questions (85)

Click any question to see the full explanation, or start a practice session above.

1

Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?

Medium
2

A CISO is building a business case for a new security tool. Which approach BEST quantifies the value of the investment?

Hard
3

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

Hard
4

During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?

Medium
5

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

Medium
6

A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?

Hard
7

Which of the following is the PRIMARY responsibility of the CISO in an organization?

Easy
8

What is the primary purpose of a security incident near-miss reporting culture?

Easy
9

Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?

Medium
10

Which TWO factors are most important when prioritizing security investments? (Select TWO.)

Medium
11

A CISO is preparing a multi-year security roadmap. Which of the following is the MOST critical factor for ensuring the roadmap aligns with business strategy?

Hard
12

Which component is essential for building a strong security culture within an organization?

Easy
13

Which metric best indicates the effectiveness of a security awareness program in changing employee behavior?

Easy
14

A CISO is reporting to the board of directors. Which metric would BEST demonstrate the effectiveness of the security program in reducing business impact?

Hard
15

An organization is updating its security policy framework. The current enterprise security policy has not been reviewed in three years. What is the FIRST step in the policy development lifecycle?

Medium
16

A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?

Medium
17

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

Easy
18

An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?

Medium
19

Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?

Easy
20

Which capability maturity model (CMM) level indicates that security processes are measured and controlled?

Easy
21

A company is considering a policy exception that would allow temporary non-compliance with a data encryption standard due to a legacy system. What is the most important element of the exception management process?

Hard
22

Which governance structure is characterized by a single security team that serves the entire organization?

Easy
23

Which regulatory requirement mandates that organizations implement data protection measures for personal data of EU citizens?

Medium
24

Which of the following is the PRIMARY reason for aligning the information security program with business objectives?

Easy
25

A multinational organization must comply with GDPR, CCPA, and PCI DSS. The security manager is designing a compliance monitoring program. Which approach is MOST efficient?

Hard
26

Which of the following is the PRIMARY benefit of having a formal policy exception management process?

Medium
27

A CISO is reporting to the board on the effectiveness of the security programme. Which TWO metrics are MOST appropriate for board-level reporting? (Select TWO)

Medium
28

An organization's security strategy includes a goal to achieve CMM Level 3. What capability does the organization need to demonstrate?

Hard
29

An organization is developing a security policy for remote access. According to the policy hierarchy, where should this policy fit?

Medium
30

A CISO is preparing a business case for a new security investment. Which TWO elements are most important to include to justify the investment?

Medium
31

A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?

Hard
32

A policy exception management process allows a business unit to temporarily deviate from a security policy. What is the MOST important requirement for such an exception?

Easy
33

A CISO is presenting a security investment proposal to the board. Which two metrics are most effective for articulating the business value of the investment?

Medium
34

A CISO is building a business case for a new security tool. Which approach BEST articulates the return on investment (ROI) to the board?

Hard
35

An organization's board of directors wants to improve security culture. Which initiative would have the GREATEST impact?

Medium
36

An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)

Hard
37

A CISO is developing a multi-year security roadmap aligned with business strategy. The organization is in a highly regulated industry with frequent regulatory changes. Which of the following should be the PRIMARY driver for prioritizing security initiatives?

Hard
38

An organization is implementing a security culture measurement program. Which THREE metrics would BEST indicate a positive security culture?

Hard
39

A CISO is building a business case for a new security tool. Which of the following approaches is MOST effective for justifying the investment?

Hard
40

Which of the following is the PRIMARY role of the board of directors in information security governance?

Medium
41

Which of the following is the primary responsibility of the board of directors in information security governance?

Easy
42

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

Medium
43

A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?

Hard
44

An organization's board of directors wants to ensure that security activities align with business objectives. Which governance practice best supports this alignment?

Medium
45

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

Easy
46

Which of the following best describes a key benefit of a centralized information security governance model?

Easy
47

Which of the following is the BEST example of a board-level security metric?

Easy
48

Which of the following is the FIRST step in the security policy development lifecycle?

Easy
49

Which TWO elements are key components of a security culture measurement program?

Easy
50

A CISO is presenting a security metrics dashboard to the board. Which TWO metrics are most appropriate for board-level reporting? (Select TWO.)

Medium
51

A security metrics program should include key performance indicators (KPIs) for board reporting. Which metric is most appropriate for executive oversight?

Easy
52

An organization is developing an information security strategy aligned with business objectives. Which of the following is the BEST approach to prioritize security investments?

Medium
53

An organization is updating its security policies. After drafting the policy, which step should occur NEXT?

Medium
54

A security awareness programme is being evaluated. Which metric BEST indicates a positive security culture?

Hard
55

Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?

Medium
56

A CISO is building a business case for a new security tool. Which TWO metrics would BEST justify the investment to senior leadership?

Medium
57

What is the first step in the security policy development lifecycle?

Easy
58

Which governance model is characterized by a single, centralized security team that serves the entire organization?

Easy
59

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

Hard
60

A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?

Medium
61

Which TWO components are essential for an effective information security governance framework?

Easy
62

Which of the following is the FIRST step in the security policy development lifecycle?

Medium
63

A CISO is developing a multi-year security roadmap. Which approach best ensures the roadmap aligns with business strategy?

Hard
64

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

Medium
65

During a policy exception review, the CISO identifies that multiple exceptions have been granted for the same control due to business constraints. What is the best course of action?

Hard
66

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

Medium
67

Which board-level committee typically receives security reports to provide oversight?

Medium
68

In a Capability Maturity Model (CMM) for information security processes, which level is characterized by processes being measured and controlled?

Medium
69

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

Medium
70

Which of the following best describes the role of the chief information security officer (CISO) in a governance context?

Medium
71

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Medium
72

The board of directors has requested a security metrics dashboard. Which metric would BEST demonstrate the effectiveness of the incident response process?

Easy
73

An organization is implementing a security awareness program. Which metric is MOST indicative of a positive security culture?

Medium
74

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

Medium
75

A company is developing a business case for a new security tool. Which metric best demonstrates the value of the investment?

Medium
76

An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?

Medium
77

An organization is designing a security metrics dashboard for the board of directors. Which THREE metrics are most appropriate for board-level reporting?

Hard
78

An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?

Medium
79

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

Medium
80

A security policy is being developed. Which THREE steps are part of the policy development lifecycle? (Select THREE)

Hard
81

An organization is updating its information security strategy. Which THREE elements should be included to ensure alignment with business objectives? (Select THREE)

Hard
82

A CISO is developing a security strategy. Which THREE elements should be included in a multi-year security roadmap?

Medium
83

An organization is subject to GDPR, PCI DSS, and SOX. What is the BEST approach to manage compliance with multiple regulations?

Hard
84

Which capability maturity model (CMM) level is characterized by security processes being standardized and documented across the organization?

Medium
85

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Hard

Frequently asked questions

What does the Information Security Governance domain cover on the CISM exam?
Information Security Governance questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 85 Information Security Governance questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Security Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism governance Practice Questions