CISM Information Security Governance Practice Question
Which board-level committee typically receives security reports to provide oversight?
⚠ Common exam trap
It's easy for candidates to confuse the audit committee's financial oversight with broader risk oversight; candidates may overlook that audit committees often have expanded risk responsibilities, including cybersecurity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit/risk committee
The audit/risk committee is typically responsible for overseeing risk management, internal controls, and compliance, making it the natural board-level committee to receive security reports. This committee ensures that security risks are aligned with the organization's risk appetite and that mitigation strategies are effective. Other committees like nominating or compensation focus on governance structure and executive pay, not security oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nominating committee
Why it's wrong here
Security oversight sits with the audit or risk committee, which reviews control assurance and risk exposure. A nominating committee handles board composition, director recruitment and governance succession, so it has no mandate to receive security reporting. It would be the right forum only when the agenda concerns board appointments or corporate governance nominations.
- ✗
Compensation committee
Why it's wrong here
The compensation committee handles executive pay, incentives and performance alignment, not security oversight. It tempts because board committees all receive governance reporting, but security reporting belongs to the risk committee, which owns enterprise risk including cyber risk. Compensation has no mandate over security posture or incident oversight.
- ✓
Audit/risk committee
Why this is correct
The audit/risk committee holds board-level oversight of risk and internal control, making it the natural recipient for security reporting. It provides independent scrutiny of risk posture and remediation, satisfying the governance requirement that security oversight sits with those accountable for enterprise risk.
- ✗
Finance committee
Why it's wrong here
The finance committee governs budgeting, audit and financial reporting, not security programme oversight. It tempts because security spending appears in budgets and audit findings, but oversight of security posture sits with the risk committee. Finance lacks the mandate to direct or challenge security risk decisions at board level.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.