Courseiva

Essential Components of an Information Security Program Charter

Which TWO of the following are essential components of an information security program charter?

⚠ Common exam trap

ISACA often tests the distinction between strategic governance documents (charter) and operational or tactical artifacts (tool lists, budgets, vendor criteria), leading candidates to select detailed implementation items that are not part of the charter's high-level scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Roles and responsibilities of key stakeholders.

The information security program charter is a high-level document that establishes the authority, scope, and governance of the security program. Roles and responsibilities of key stakeholders (Option B) are essential because they define accountability and decision-making authority, ensuring the program has clear ownership and oversight. Program scope and objectives (Option D) are equally essential as they set the boundaries and goals of the security program, aligning it with business strategy and risk appetite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List of specific security tools to be deployed.

    Why it's wrong here

    A charter defines scope, authority, mandate and governance, not procurement detail; naming tools belongs in a technical architecture or deployment plan, and would date the charter as products change. It tempts because tool inventories feel concrete, yet they are an implementation output, not an authorising component.

  • ✓

    Roles and responsibilities of key stakeholders.

    Why this is correct

    Assigning roles and responsibilities names who owns, operates and oversees the security programme, satisfying the charter's need for clear accountability. It establishes decision rights and reporting lines across stakeholders, ensuring governance duties are not left ambiguous as the programme is authorised and resourced.

  • ✗

    Vendor selection criteria.

    Why it's wrong here

    Vendor selection criteria govern procurement decisions, not the security programme's mandate, scope or governance. It is tempting because third-party risk belongs in security policy, and would be correct within a supplier management or procurement policy rather than the charter itself.

  • ✓

    Program scope and objectives.

    Why this is correct

    Defining programme scope and objectives sets the charter's boundaries and intended outcomes, satisfying the requirement that the mandate be explicitly documented. It clarifies which assets, business units and risks the information security programme covers, giving management an approved baseline against which performance is later measured.

  • ✗

    Detailed budget allocation.

    Why it's wrong here

    Detailed budget allocation is a financial planning artefact, whereas the charter establishes mandate, scope, authority and accountability. It is tempting because funding underpins any programme, and would be correct within a budget plan or business case rather than the charter.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.