mediumMultiple Select
Board of Directors Responsibilities in Information Security Governance
Which THREE of the following are responsibilities of the board of directors regarding information security governance?
Quick Answer
The answer is setting the organization’s risk appetite, along with approving the security strategy and authorizing the budget. These three responsibilities are correct because the board of directors operates at a strategic governance level, defining the boundaries of acceptable risk and ensuring resources align with that direction. On the Certified Information Security Manager CISM exam, this question tests your understanding of the separation between governance and management: the board owns the “what” and “how much” of risk, while operational tasks like vulnerability scans and incident response fall to technical staff and management. A common trap is confusing the board’s oversight role with hands-on activities—remember, the board does not execute, it authorizes. For a memory tip, think of the three B’s: Board sets the Boundaries (risk appetite), Blesses the strategy, and Budgets the resources.
⚠ Common exam trap
It's easy for candidates to confuse governance (board-level strategic oversight) with management (operational execution), leading candidates to select hands-on tasks like incident response or vulnerability scanning as board responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approve the information security strategy
Option A is correct because the board of directors is responsible for approving the information security strategy, ensuring it aligns with business objectives and regulatory obligations at the highest governance level. Option D is correct because authorizing the security budget is a board-level fiduciary duty that allocates resources to implement and sustain the security program. Option E is correct because setting the organization's risk appetite is a core governance responsibility of the board, defining how much risk the organization is willing to accept in pursuit of its goals. Options B and C are incorrect because responding to security incidents and conducting vulnerability scans are operational and technical tasks performed by security operations teams, not by the board of directors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Approve the information security strategy
Why this is correct
Approving the information security strategy is a governance function reserved for the board, ensuring security direction aligns with business objectives and risk tolerance. Management drafts and executes the strategy, but board endorsement satisfies the stem's requirement for a board-level responsibility.
- ✗
Respond to security incidents
Why it's wrong here
Incident response is an operational task executed by the security team and management, not board-level governance. The board sets direction, approves strategy and oversees risk appetite. Responding to incidents would be the right answer if the question asked about operational security roles rather than governance responsibilities.
- ✗
Conduct vulnerability scans
Why it's wrong here
Vulnerability scanning is a hands-on technical activity performed by security operations staff, not directors. The board provides oversight, approves security strategy and monitors risk. Conducting scans would be correct if the question asked about operational security duties instead of governance responsibilities.
- ✓
Authorize the security budget
Why this is correct
Authorising the security budget is a board governance responsibility, since resource allocation determines whether the security strategy can be delivered. This satisfies the stem by keeping funding authority at oversight level, distinct from management's operational spending decisions.
- ✓
Set the organization's risk appetite
Why this is correct
Setting risk appetite is inherently a board duty: it establishes the acceptable level of information security risk the organisation will tolerate. This satisfies the stem's governance constraint because appetite guides strategy and investment, and cannot be delegated to the management layer being overseen.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the PRIMARY role of the board of directors in information security governance?
easy- A.Managing the day-to-day security operations.
- B.Implementing security controls and technologies.
- ✓ C.Providing strategic direction and oversight of the security program.
- D.Developing detailed security policies and procedures.
Why C: The board of directors holds the ultimate fiduciary responsibility for the organization, including its information security posture. Their primary role is to provide strategic direction and oversight, ensuring that the security program aligns with business objectives, risk appetite, and regulatory requirements. This includes approving the overall security strategy, reviewing key risk indicators, and holding management accountable for security performance, not executing tactical tasks.
Variation 2. Which TWO of the following are primary responsibilities of the board of directors with regard to information security governance? (Select exactly two.)
easy- A.Performing vulnerability scans
- B.Implementing security controls
- ✓ C.Ensuring security strategy aligns with business goals
- ✓ D.Approving the information security risk appetite
- E.Conducting daily security monitoring
Why C: Option C is correct because the board of directors is responsible for governance, which means ensuring that the organization's information security strategy is aligned with and supports the overall business goals and objectives. Option D is correct because setting and approving the organization's risk appetite—the amount and type of risk it is willing to accept—is a core governance responsibility that belongs to the board, which then guides management's security decisions. Options A, B, and E are incorrect because performing vulnerability scans, implementing security controls, and conducting daily security monitoring are operational, hands-on tasks carried out by security practitioners and management, not by the board of directors.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.