mediumMultiple SelectObjective-mapped
COBIT Governance Framework Components
Which TWO of the following are essential components of an information security governance framework according to ISACA's COBIT?
Quick Answer
The answer is strategic alignment and value delivery. These two are essential components of the COBIT governance framework because they directly address the core governance objectives of linking IT security to business goals and ensuring that security investments generate measurable business benefits. In the Certified Information Security Manager CISM exam, this question tests your ability to distinguish between high-level governance principles and lower-level operational or technical controls. A common trap is confusing performance measurement, which is a supporting enabler, with the foundational governance components, or mistaking incident response or firewall configuration—both operational activities—for governance elements. To remember this, think of the acronym SAVE: Strategic alignment and Value delivery are the two governance pillars, while the rest are just tools.
⚠ Common exam trap
Many candidates confuse operational security activities (like incident response or firewall configuration) with governance-level components, failing to recognize that COBIT's governance framework focuses on strategic alignment and value delivery rather than technical controls or performance measurement as a core pillar.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Value delivery
Value delivery is a core component of ISACA's COBIT framework for information security governance, as it ensures that security investments directly support business objectives and provide measurable benefits. COBIT defines value delivery as the process of optimizing security-related costs while maximizing the return on investment through effective risk management and resource allocation. This aligns with the governance objective of balancing value creation with risk mitigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Value delivery
Why this is correct
A core component ensuring security investments bring value.
- ✗
Performance measurement
Why it's wrong here
While part of governance, it is considered an enabler, not a core component.
- ✓
Strategic alignment
Why this is correct
A core component ensuring security supports business objectives.
- ✗
Incident response playbook
Why it's wrong here
This is an operational procedure, not governance.
- ✗
Firewall configuration
Why it's wrong here
This is an operational control, not a governance component.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are key elements of an information security governance framework, as defined by COBIT?
easy- ✓ A.Value delivery
- B.Incident response
- C.Resource management
- ✓ D.Strategic alignment
- E.Risk management
Why A: COBIT identifies strategic alignment and value delivery as two key elements of an information security governance framework. Value delivery (A) is correct because it ensures that security investments directly support business objectives and provide measurable benefits. Strategic alignment (D) is correct because it ensures that security activities are aligned with the enterprise's overall strategy. The other options—incident response, resource management, and risk management—are important operational or supporting processes but are not considered primary governance framework elements under this definition.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.