Courseiva

CISM Information Security Governance Practice Question

In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?

⚠ Common exam trap

CISM often tests the distinction between solid and dotted reporting lines, and candidates frequently confuse which line represents primary authority versus secondary coordination, leading them to select an option that reverses the lines or creates dual solid reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Solid line to CEO, dotted line to CIO

A solid reporting line indicates primary authority, accountability, and usually administrative control (e.g., performance reviews, budget, hiring/firing). A dotted line indicates a secondary, functional, or operational reporting relationship. In this model, the CISO's primary accountability is to the CEO, ensuring independence from IT operations, while the dotted line to the CIO allows for coordination on operational matters like security tool deployment or incident response. This dual reporting structure is common in organizations seeking to balance security independence with operational efficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Solid line to CEO, dotted line to CIO

    Why this is correct

    A solid line to the CEO grants the CISO authority, budget and escalation rights, while the dotted line to the CIO preserves operational coordination. This satisfies the stem's dual-reporting requirement by separating governance accountability from day-to-day IT alignment, preventing the CIO from filtering security concerns before they reach executive leadership.

  • ✗

    Solid line to CIO, dotted line to CEO

    Why it's wrong here

    A solid line to the CIO makes the CIO the CISO's direct manager, contradicting the required direct reporting line to the CEO. This structure is tempting because it preserves CIO operational oversight, but it subordinates security to IT rather than giving the CISO direct CEO accountability.

  • ✗

    Dotted line to both CEO and CIO

    Why it's wrong here

    A dotted line to both gives the CEO no direct authority over the CISO, so accountability for security remains ambiguous. Dual dotted reporting is tempting when balancing executive visibility with operational oversight, but the stem requires a direct line to the CEO plus operational reporting to the CIO.

  • ✗

    Solid line to both CEO and CIO

    Why it's wrong here

    Two solid lines create dual authority, leaving the CISO answerable to both executives with no single escalation path. It is tempting as a way to give security equal standing with IT, but the stem specifies one direct line to the CEO and only operational reporting to the CIO.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.