Courseiva
hardMultiple ChoiceObjective-mapped

Best Governance Committee Composition

A global company is establishing an information security governance committee. Which membership composition BEST ensures alignment between security and business strategy?

Quick Answer

The answer is a governance committee composed of senior leaders from each business unit, the CISO, and the Chief Risk Officer. This composition best ensures alignment between security and business strategy because it creates a cross-functional governance body that integrates diverse operational perspectives with risk and security expertise, enabling strategic decisions that balance protection with business objectives. On the CISM exam, this tests your understanding of governance committee membership best composition as a core concept of information security governance, often appearing in questions that contrast broad business representation with narrow functional groups. A common trap is choosing IT-heavy or finance-only memberships, which lack the authority and business context needed for true strategic alignment. Remember the memory tip: “Three pillars of governance—business, security, and risk”—ensuring every major stakeholder voice is at the table.

⚠ Common exam trap

Many exam-takers assume a committee composed solely of IT and security roles (like the CISO and IT directors) is sufficient, but CISM emphasizes that governance requires cross-functional senior leadership to ensure security is a business enabler, not just a technical function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Senior leaders from each business unit, the CISO, and the Chief Risk Officer

It ensures that the information security governance committee includes senior leaders from each business unit, the CISO, and the Chief Risk Officer. This composition directly aligns security initiatives with business strategy by integrating business objectives, risk appetite, and security expertise at the strategic decision-making level, which is essential for effective governance as defined by ISACA's CISM framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IT operations managers and the CISO

    Why it's wrong here

    Too focused on IT, not business.

  • Chief Information Security Officer (CISO) and IT directors only

    Why it's wrong here

    Excludes business stakeholders.

  • Senior leaders from each business unit, the CISO, and the Chief Risk Officer

    Why this is correct

    Ensures business alignment and risk integration.

  • Chief Financial Officer (CFO), General Counsel, and CISO

    Why it's wrong here

    Lacks representation from operational business units.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's security steering committee includes representatives from Human Resources, Legal, and Risk Management, but not from Business Operations. What is the most likely consequence of this membership gap?

medium
  • A.Data breaches will occur more frequently
  • B.Security policies may not align with operational processes
  • C.Security spending will increase unexpectedly
  • D.The company will face regulatory fines

Why B: Without Business Operations representation, the security steering committee lacks direct insight into how security policies will interact with day-to-day operational workflows. This gap often results in policies that are technically sound but impractical to implement, causing misalignment with existing processes and potential operational friction.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.