CISM Steering committee primary role? Practice Question
Which of the following is the PRIMARY responsibility of a steering committee in an information security program?
⚠ Common exam trap
A common mix-up: candidates confuse the steering committee's strategic oversight role with the tactical or operational duties of other roles, such as the CISO or security analysts, leading them to select options like approving policies or conducting assessments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Providing strategic direction and oversight
The steering committee's primary role is to provide strategic direction and oversight for the information security program, ensuring alignment with business objectives and risk appetite. This includes approving the overall security strategy, budget, and major initiatives, rather than engaging in operational tasks like policy drafting or technical assessments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approving individual security policies
Why it's wrong here
Approving individual policies is a governance-adjacent task usually delegated to the CISO or policy owners; the steering committee approves the overarching security strategy, charter and risk appetite. It tempts because committees do sanction policy frameworks, but granular approval is not their primary responsibility.
- ✓
Providing strategic direction and oversight
Why this is correct
Providing strategic direction and oversight is the steering committee's core mandate: aligning the security programme with business objectives, approving risk appetite, and prioritising funding. This satisfies the stem's demand for the *primary* responsibility, distinguishing governance-level direction from the operational execution handled by security management and practitioners.
- ✗
Conducting vulnerability assessments
Why it's wrong here
Vulnerability assessments are operational testing performed by security staff or assessors; a steering committee sets strategic direction, prioritisation and risk acceptance. The option tempts because assessment findings often reach the committee for decisions, but execution stays with technical teams.
- ✗
Implementing security controls
Why it's wrong here
Implementing controls is an operational task owned by security and IT engineering teams; the steering committee provides oversight, resourcing and strategic alignment. It tempts because committee decisions authorise control deployments, yet hands-on configuration and rollout remain outside its remit.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Providing strategic direction and oversightCorrect answer▾
Why this is correct
Providing strategic direction and oversight is the steering committee's core mandate: aligning the security programme with business objectives, approving risk appetite, and prioritising funding. This satisfies the stem's demand for the *primary* responsibility, distinguishing governance-level direction from the operational execution handled by security management and practitioners.
✗Approving individual security policiesWrong answer — click to see why▾
Why this is wrong here
Policy approval is an operational task, not the primary strategic role of the steering committee.
✗Conducting vulnerability assessmentsWrong answer — click to see why▾
Why this is wrong here
Technical assessments are performed by operational teams, not the steering committee.
✗Implementing security controlsWrong answer — click to see why▾
Why this is wrong here
Implementation is an operational responsibility, not a steering committee function.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.