Courseiva
easyMultiple Choice

CISM Practice Question: Is the PRIMARY role of the board of directors in…

Which of the following is the PRIMARY role of the board of directors in information security governance?

⚠ Common exam trap

ISACA often tests the distinction between governance (board) and management (CISO/IT) roles, and the trap here is that candidates mistakenly assign tactical implementation duties to the board because they confuse oversight with execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Providing strategic direction and oversight of the security program.

The board of directors holds the ultimate fiduciary responsibility for the organization, including its information security posture. Their primary role is to provide strategic direction and oversight, ensuring that the security program aligns with business objectives, risk appetite, and regulatory requirements. This includes approving the overall security strategy, reviewing key risk indicators, and holding management accountable for security performance, not executing tactical tasks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Managing the day-to-day security operations.

    Why it's wrong here

    Day-to-day operational management is delegated to security leadership and operational staff; the board provides oversight, approves risk appetite and monitors whether security aligns with business objectives. Operational involvement is tempting because boards are accountable for outcomes, yet directing daily activity erodes that oversight independence.

  • ✗

    Implementing security controls and technologies.

    Why it's wrong here

    Implementing controls and technologies is an operational and engineering task performed by security and IT teams; the board governs by setting direction, resourcing and monitoring risk. Hands-on implementation is tempting because boards approve funding, but selecting and deploying controls sits firmly with management.

  • ✓

    Providing strategic direction and oversight of the security program.

    Why this is correct

    The board sets risk appetite and strategic direction, then oversees whether the security programme aligns with business objectives and regulatory obligations. This satisfies the governance requirement for top-level accountability, distinct from management's operational implementation of controls.

  • ✗

    Developing detailed security policies and procedures.

    Why it's wrong here

    Drafting policies and procedures is management's execution work, delegated to the CISO and security teams; the board sets risk appetite, oversees strategy and holds executives accountable. Policy authorship is tempting because boards approve high-level policy, but detailed procedural content belongs below governance level.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.