Courseiva

CISM · topic practice

Information Security Governance practice questions

Domain 1 of the CISM exam covers establishing and maintaining an information security governance framework that aligns security strategy with business objectives. Questions test governance structures, roles and reporting lines, regulatory and legal drivers, policy hierarchy, risk appetite, metrics reported to the board, and how security culture and third-party relationships are governed and measured.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Security Governance

What the exam tests

What to know about Information Security Governance

Be able to align security governance with business strategy, assign accountability correctly, and pick metrics the board can act on. The single most important thing: prioritize and decide based on business risk and regulatory obligation, not on technology preference or security team convenience.

Aligning security strategy and roadmap priorities with business objectives, risk appetite, and regulatory obligations

Assigning governance accountability across the board, steering committee, CISO, and business process owners

Applying policy hierarchy: enterprise policy, standards, baselines, procedures, and guidelines

Selecting board-level metrics such as incident response effectiveness, control coverage, and culture indicators

Watch out for

Common Information Security Governance exam traps

  • ▸Treating technology tools or vendor products as the primary driver of roadmap priorities instead of business risk and strategy
  • ▸Assuming the CISO or security team owns all risk, rather than business process owners accepting and owning risk
  • ▸Choosing operational metrics like patch counts or alert volumes when the question asks for board-level governance metrics

Practice set

Information Security Governance questions

20 questions · select your answer, then reveal the explanation

During a security policy development lifecycle, which step should occur immediately after 'drafting' the policy?

A security manager is conducting a regulatory compliance review. Which THREE regulations are most likely to apply to a financial services company operating in the United States?

Which capability maturity model (CMM) level indicates that security processes are managed and measured using quantitative metrics?

An organization is updating its security policies. After drafting the policy, which step should occur NEXT?

A CISO is designing a security metrics program for the board. Which TWO metrics are MOST appropriate for board-level reporting?

A CISO reports to the CIO and provides regular security updates to the board audit committee. The CEO has delegated security accountability to the CFO. Which governance structure does this reflect?

What is the first step in the security policy development lifecycle?

Which of the following is the PRIMARY reason for aligning the information security program with business objectives?

In a Capability Maturity Model (CMM) for information security processes, which level is characterized by processes being measured and controlled?

An organization is developing a security policy for remote access. According to the policy hierarchy, where should this policy fit?

Which of the following is the PRIMARY role of the board of directors in information security governance?

Which of the following is the FIRST step in the security policy development lifecycle?

An organization is implementing a policy exception management process. Which THREE elements are essential for effective exception handling? (Select THREE.)

An organization is implementing a security culture measurement program. Which THREE metrics would BEST indicate a positive security culture?

The board of a multinational bank has directed the CISO to establish a formal information security governance framework. Executive management wants assurance that security activities are aligned with business objectives and that risks are managed effectively. Which of the following is the MOST important first step in establishing this framework?

A CISO is developing a business case for a new security investment. The organization's governance requires that security investments be justified by business value. Which two factors are MOST important to include in the business case? (Choose two.)

A global retail company is revising its information security strategy to better align with business goals. The CISO has proposed a new governance model that includes a security steering committee. Which of the following should be the PRIMARY responsibility of this committee?

Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?

An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?

A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Security Governance sessions

Start a Information Security Governance only practice session

Every question in these sessions is drawn from the Information Security Governance domain — nothing else.

Related practice questions

Related CISM topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISM exam test about Information Security Governance?
Be able to align security governance with business strategy, assign accountability correctly, and pick metrics the board can act on. The single most important thing: prioritize and decide based on business risk and regulatory obligation, not on technology preference or security team convenience.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Security Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Security Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISM topics?
Use the topic links above to move to related areas, or go back to the CISM question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISM exam covers. They are not copied from any real exam or dump site.