CISM Information Security Governance Practice Question
In which reporting model does the CISO have a direct reporting line to the CEO while also reporting to the CIO on operational matters?
⚠ Common exam trap
CISM often tests the distinction between solid and dotted reporting lines, and candidates frequently confuse which line represents primary authority versus secondary coordination, leading them to select an option that reverses the lines or creates dual solid reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Solid line to CEO, dotted line to CIO
A solid reporting line indicates primary authority, accountability, and usually administrative control (e.g., performance reviews, budget, hiring/firing). A dotted line indicates a secondary, functional, or operational reporting relationship. In this model, the CISO's primary accountability is to the CEO, ensuring independence from IT operations, while the dotted line to the CIO allows for coordination on operational matters like security tool deployment or incident response. This dual reporting structure is common in organizations seeking to balance security independence with operational efficiency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Solid line to CEO, dotted line to CIO
Why this is correct
A solid line to the CEO grants the CISO authority, budget and escalation rights, while the dotted line to the CIO preserves operational coordination. This satisfies the stem's dual-reporting requirement by separating governance accountability from day-to-day IT alignment, preventing the CIO from filtering security concerns before they reach executive leadership.
- ✗
Solid line to CIO, dotted line to CEO
Why it's wrong here
A solid line to the CIO makes the CIO the CISO's direct manager, contradicting the required direct reporting line to the CEO. This structure is tempting because it preserves CIO operational oversight, but it subordinates security to IT rather than giving the CISO direct CEO accountability.
- ✗
Dotted line to both CEO and CIO
Why it's wrong here
A dotted line to both gives the CEO no direct authority over the CISO, so accountability for security remains ambiguous. Dual dotted reporting is tempting when balancing executive visibility with operational oversight, but the stem requires a direct line to the CEO plus operational reporting to the CIO.
- ✗
Solid line to both CEO and CIO
Why it's wrong here
Two solid lines create dual authority, leaving the CISO answerable to both executives with no single escalation path. It is tempting as a way to give security equal standing with IT, but the stem specifies one direct line to the CEO and only operational reporting to the CIO.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.