mediumMultiple Select
CISM Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of an information security governance framework? (Choose two.)
⚠ Common exam trap
Candidates often confuse operational security controls (like IDS configuration or firewall rules) or compliance outputs (like PCI DSS reports) with the strategic governance components, which are policy, standards, and risk management processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policy and standards.
Security policy and standards are foundational components of an information security governance framework because they establish the high-level direction, principles, and mandatory requirements that guide the organization's security posture. The risk management process is equally critical as it provides a structured methodology for identifying, assessing, and treating risks, ensuring that security decisions are aligned with business objectives and risk appetite. Together, they form the strategic and operational backbone of governance, enabling accountability and continuous improvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security policy and standards.
Why this is correct
Security policy and standards translate management's risk appetite into enforceable directives, defining acceptable use, control baselines and accountability. They are the foundational governance artefacts that direct and constrain security activity, satisfying the framework's requirement for documented direction and measurable compliance criteria.
- ✗
Intrusion detection system (IDS) configuration.
Why it's wrong here
An IDS configuration is an operational security control, not a governance component; governance sets direction, risk appetite and oversight rather than tuning detection signatures. It is tempting because IDS monitoring evidences control effectiveness, and it would be the right answer if the question asked which technical controls support security operations.
- ✗
Firewall rule set.
Why it's wrong here
A firewall rule set is a technical access control, not part of the governance framework, which defines strategy, roles, policy and risk tolerance. It is tempting because firewalls enforce governance decisions, and a rule set would be correct if the question asked which artefacts implement network access policy.
- ✗
Payment Card Industry Data Security Standard (PCI DSS) compliance report.
Why it's wrong here
A PCI DSS compliance report evidences conformance with one external standard; governance frameworks derive from organisational strategy and risk appetite, not a single regulatory report. It is tempting because compliance reporting demonstrates oversight, and it would be correct if the question asked which artefacts provide assurance to regulators.
- ✓
Risk management process.
Why this is correct
A risk management process identifies, assesses and treats information security risks, aligning controls with organisational risk appetite. It is a core governance component because it directs resource allocation and ensures security decisions are driven by business risk rather than technical preference alone.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.