CISM Information Security Governance Practice Question
Which of the following is the primary responsibility of the board of directors in information security governance?
⚠ Common exam trap
CISM often tests the board's strategic governance role versus management's operational role — candidates may pick 'writing security policies' because it sounds authoritative, but policy authoring is a management function while risk appetite setting is a board function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Setting risk appetite and overseeing security governance
The board of directors' primary responsibility in information security governance is setting the organization's risk appetite and overseeing security governance to ensure it aligns with business objectives. The board defines how much risk the organization is willing to accept, approves the security strategy, and monitors management's execution — it does not perform operational or policy-writing tasks. This ensures security is governed at the highest level and integrated with business strategy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementing day-to-day security operations
Why it's wrong here
Day-to-day security operations belong to the CISO and security team, not the board. Directors set risk appetite, approve strategy and oversee governance; delegating implementation to them inverts the accountability model. Boards would own operational tasks only in very small organisations lacking a security function.
- ✗
Conducting vulnerability assessments
Why it's wrong here
Vulnerability assessments are an operational, technical activity executed by security staff and reported upward; the board sets risk appetite, strategy and oversight. It would be the correct responsibility for a penetration testing team or vulnerability management function, not for directors.
- ✓
Setting risk appetite and overseeing security governance
Why this is correct
The board owns governance, not operational security. Setting the organisation's risk appetite defines how much risk is acceptable, and overseeing governance ensures security aligns with strategy. This satisfies the stem's governance-level responsibility, distinct from management's implementation duties.
- ✗
Writing security policies
Why it's wrong here
Policy drafting is delegated to the CISO and security team, with the board approving and endorsing the resulting framework rather than authoring text. Directors own governance direction, risk tolerance and accountability. Writing policies would be the correct task for a security manager or policy owner.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.