mediumMultiple SelectObjective-mapped
CISM Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of an information security governance framework? (Choose two.)
⚠ Common exam trap
Candidates often confuse operational security controls (like IDS configuration or firewall rules) or compliance outputs (like PCI DSS reports) with the strategic governance components, which are policy, standards, and risk management processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policy and standards.
Security policy and standards are foundational components of an information security governance framework because they establish the high-level direction, principles, and mandatory requirements that guide the organization's security posture. The risk management process is equally critical as it provides a structured methodology for identifying, assessing, and treating risks, ensuring that security decisions are aligned with business objectives and risk appetite. Together, they form the strategic and operational backbone of governance, enabling accountability and continuous improvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security policy and standards.
Why this is correct
Foundational elements of governance frameworks.
- ✗
Intrusion detection system (IDS) configuration.
Why it's wrong here
Operational tool, not a governance framework component.
- ✗
Firewall rule set.
Why it's wrong here
Technical control, not governance framework component.
- ✗
Payment Card Industry Data Security Standard (PCI DSS) compliance report.
Why it's wrong here
Compliance artifact, not a governance framework component.
- ✓
Risk management process.
Why this is correct
Core component of governance frameworks.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.