Courseiva
hardMultiple Select

CISM Practice Question: Which THREE of the following are essential…

Which THREE of the following are essential components of a mature information security governance framework?

⚠ Common exam trap

ISACA often tests the distinction between governance (strategic oversight) and management (operational execution), so the trap here is confusing operational components like a SOC or full compliance with the foundational governance elements of risk appetite, performance measurement, and strategic alignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A formally defined and approved risk appetite statement.

Option A is correct because a formally defined and approved risk appetite statement is a foundational governance artifact: it expresses how much risk the organization is willing to accept, enabling consistent risk-based decisions and prioritization across the security program. Option B is correct because governance requires accountability and oversight, which are achieved through performance measurement and reporting mechanisms that give the board and executives visibility into security posture, metrics, and progress against objectives. Option D is correct because strategic alignment between security objectives and business goals ensures security is integrated into enterprise strategy rather than treated as an isolated technical function, which is a core principle of governance frameworks such as ISO/IEC 27001 and COBIT. Option C does not belong because compliance with regulatory requirements is a baseline obligation and an outcome of governance, not an essential structural component; a mature framework may exceed or go beyond mere compliance. Option E does not belong because a dedicated 24/7 SOC is an operational capability that supports detection and response, not a required element of a governance framework, and many mature governance programs operate effectively without one.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A formally defined and approved risk appetite statement.

    Why this is correct

    A board-approved risk appetite statement defines how much risk the organisation accepts, giving governance decisions a formal baseline. It satisfies the framework's requirement for documented direction, ensuring security investment and tolerance align with business strategy rather than ad hoc judgement.

  • ✓

    Performance measurement and reporting mechanisms for the board.

    Why this is correct

    Board-level performance measurement and reporting mechanisms provide governance oversight, satisfying the framework's requirement for accountability. Metrics let directors verify that security controls and risk treatments operate effectively, closing the loop between strategy, execution and assurance.

  • ✗

    Full compliance with all relevant regulatory requirements.

    Why it's wrong here

    Full regulatory compliance is an outcome of governance, not one of its components; frameworks require policy, risk management, roles and performance measurement. It is tempting because compliance obligations drive governance scope, and would be correct when identifying an external driver prompting a governance programme.

  • ✓

    Strategic alignment between security objectives and business goals.

    Why this is correct

    Strategic alignment ensures security controls directly support business objectives rather than operating as an isolated technical function, satisfying the governance requirement that security strategy derives from and remains traceable to organisational goals. This linkage enables risk decisions to be made at the appropriate business level, which is fundamental to mature governance under CISM's enterprise-wide perspective.

  • ✗

    A dedicated security operations center (SOC) with 24/7 monitoring.

    Why it's wrong here

    A 24/7 SOC is a monitoring capability delivering operational detection, not a governance component such as strategy, policy, roles or assurance reporting. It is tempting because continuous monitoring evidences control effectiveness, and would be correct when asked which capability supports incident detection and response.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.