CISM Information Security Governance Practice Question
Which of the following is the correct order in the security policy hierarchy, from highest to lowest level?
⚠ Common exam trap
CISM often tests the hierarchy by shuffling the order — candidates who memorise 'policy, standard, procedure, guideline' as a phrase can still be caught by reversed or partially reordered options, so the trap is failing to anchor on authority decreasing top-to-bottom.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enterprise Policy, Standards, Procedures, Guidelines
The security policy hierarchy flows from the highest-level, most enduring document to the most detailed and changeable: Enterprise Policy (management's intent and mandatory requirements), then Standards (specific mandatory controls and configurations), then Procedures (step-by-step instructions to implement standards), then Guidelines (non-mandatory recommendations and best practice). This ordering reflects decreasing authority and increasing operational detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standards, Enterprise Policy, Procedures, Guidelines
Why it's wrong here
Standards sit below enterprise policy, so placing them first inverts the hierarchy; procedures and guidelines are subordinate again. Standards are mandatory, technology-specific specifications that operationalise policy, and would correctly lead only if the question asked for the level directly beneath enterprise policy rather than the full ordering from highest to lowest.
- ✗
Procedures, Standards, Enterprise Policy, Guidelines
Why it's wrong here
Procedures sit below standards and guidelines, so this inverts the hierarchy entirely. It tempts because procedures are mandatory and operational, and in some governance models they are grouped with standards; but enterprise policy always occupies the top tier, with guidelines lowest as non-mandatory recommendations.
- ✗
Guidelines, Procedures, Standards, Enterprise Policy
Why it's wrong here
Guidelines sit below standards and procedures, so placing them highest inverts the hierarchy. Guidelines are non-mandatory recommendations that support policy, not govern it. They would be the right answer only if the question asked which document offers discretionary advice to help staff comply with mandatory requirements.
- ✓
Enterprise Policy, Standards, Procedures, Guidelines
Why this is correct
Enterprise policy states management's intent at the highest level; standards then mandate specific controls; procedures describe step-by-step implementation; guidelines offer optional recommended practise. This descending order of authority and specificity matches the hierarchy the question requires.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.