Courseiva
mediumMultiple Select

CISM Practice Question: Which TWO of the following are essential…

Which TWO of the following are essential components of an effective information security governance framework? (Select exactly two.)

⚠ Common exam trap

Many exam-takers confuse operational security tools (SIEM, patch management, IPS) with governance components, which are about strategy, roles, and oversight, not specific technologies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Process for aligning security strategy with business strategy

Option C is correct because information security governance fundamentally requires a process that aligns the security strategy with the organization's business strategy, ensuring security investments and priorities directly support business objectives and risk appetite. Option E is correct because governance depends on clearly defined roles and responsibilities for security decisions, establishing accountability and authority (for example, who approves policy, who accepts risk, and who reports to the board) so decisions are made and enforced consistently. Options A, B, and D are incorrect because a SIEM system, automated patch management, and an IPS are technical security controls that support operations and defense-in-depth, but they are implementation tools rather than essential governance framework components; governance is about direction, alignment, and accountability, not specific technologies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementation of a SIEM system

    Why it's wrong here

    A SIEM aggregates and correlates logs for detection and response; it is a monitoring tool, not a governance component such as strategy, roles, or risk appetite. It is tempting because SIEM underpins operational security oversight, and would be the right answer if the question asked which technology supports security operations monitoring.

  • ✗

    Automated patch management system

    Why it's wrong here

    Automated patch management is an operational vulnerability-remediation control, not part of the governance framework itself; governance comprises direction-setting elements such as policies, roles, risk appetite and performance measurement. It is tempting because patching is essential to security programmes, and it would be correct if the question asked about operational controls rather than governance.

  • ✓

    Process for aligning security strategy with business strategy

    Why this is correct

    Governance fails when security operates in isolation from organisational objectives. A defined process aligning security strategy with business strategy ensures controls and investment directly support business goals, priorities and risk appetite, rather than being technology-driven and disconnected from value delivery.

  • ✗

    Intrusion prevention system (IPS)

    Why it's wrong here

    An IPS is a technical control that blocks malicious traffic, not a governance component; governance covers strategy, policy, risk management and oversight structures. It is tempting because security technologies are often listed alongside governance items, and an IPS would be the right answer to a question about operational threat prevention controls.

  • ✓

    Defined roles and responsibilities for security decisions

    Why this is correct

    Governance requires clear accountability, not diffuse ownership. Explicitly defined roles and responsibilities for security decisions ensure each control, risk acceptance and policy question has a named owner, preventing gaps and duplicated effort across the organisation.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.