easyMultiple SelectObjective-mapped
CISM Practice Question: Which TWO of the following are primary…
Which TWO of the following are primary responsibilities of the board of directors in information security governance?
⚠ Common exam trap
A common pitfall in CISM questions is confusing the board's strategic governance duties (approving risk appetite, holding management accountable) with management's operational tasks (implementing controls, designing architecture).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approving the organization's information security risk appetite.
The board of directors is responsible for setting the organization's risk appetite, which defines the acceptable level of risk in information security. This is a strategic governance decision that guides all subsequent security activities. Approving the risk appetite ensures that security investments align with business objectives and regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Approving the organization's information security risk appetite.
Why this is correct
The board sets the risk appetite.
- ✗
Implementing security controls to mitigate identified risks.
Why it's wrong here
Implementation is management's responsibility.
- ✗
Designing the technical security architecture for the organization.
Why it's wrong here
Architecture is typically a technical management role.
- ✓
Holding executive management accountable for the effectiveness of the security program.
Why this is correct
The board oversees and holds management accountable.
- ✗
Conducting internal security audits of the information systems.
Why it's wrong here
Audits are performed by internal audit or third parties, not the board.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.