Courseiva
Question 762 of 871
Information Security ProgrammediumMatchingObjective-mapped

CISM Information Security Program Practice Question

Match each security framework to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Specify requirements for an ISMS

Provide risk-based guidance for critical infrastructure

Govern and manage enterprise IT

Align IT services with business needs

Protect cardholder data

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

COBIT: A framework for IT governance and management.

COBIT is for IT governance, ISO 27001 for ISMS, and NIST CSF for cybersecurity risk management. The distractors swap definitions between COBIT and ISO 27001.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • COBIT: A framework for IT governance and management.

    Why this is correct

    COBIT is specifically designed for IT governance and management, providing a comprehensive framework for aligning IT with business goals.

  • ISO 27001: A standard for information security management systems.

    Why this is correct

    ISO 27001 is an international standard that specifies requirements for establishing, implementing, and maintaining an information security management system (ISMS).

  • NIST Cybersecurity Framework: A framework to improve cybersecurity risk management.

    Why this is correct

    The NIST Cybersecurity Framework provides guidance for organizations to better understand, manage, and reduce cybersecurity risks.

  • COBIT: A standard for information security management systems.

    Why it's wrong here

    Incorrect — this definition describes ISO 27001, not COBIT. COBIT focuses on IT governance.

  • ISO 27001: A framework for IT governance and management.

    Why it's wrong here

    Incorrect — this definition describes COBIT, not ISO 27001. ISO 27001 is an ISMS standard.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.