easyMultiple Select
CISM Practice Question: Which TWO of the following are primary…
Which TWO of the following are primary responsibilities of the board of directors in information security governance?
⚠ Common exam trap
A common pitfall in CISM questions is confusing the board's strategic governance duties (approving risk appetite, holding management accountable) with management's operational tasks (implementing controls, designing architecture).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approving the organization's information security risk appetite.
Option A is correct because setting and approving the organization's information security risk appetite is a core governance responsibility of the board, which defines how much risk the enterprise is willing to accept in pursuit of its objectives. Option D is correct because the board provides oversight by holding executive management accountable for the effectiveness of the security program, ensuring security aligns with business strategy and risk tolerance. Options B, C, and E are incorrect because implementing security controls, designing technical security architecture, and conducting internal security audits are operational and technical activities delegated to management, security architects, and internal audit or assurance functions, not the board itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Approving the organization's information security risk appetite.
Why this is correct
Setting risk appetite is a board-level governance duty: it defines how much information security risk the organisation is willing to accept, which then bounds management's strategy and controls. This satisfies the stem's requirement for a primary board responsibility rather than an operational task delegated to management.
- ✗
Implementing security controls to mitigate identified risks.
Why it's wrong here
Implementing controls is an operational, management-level activity executed by security and IT staff; the board sets risk appetite, approves strategy and monitors outcomes. Boards would own control implementation only in very small organisations lacking a management layer, which governance frameworks do not assume.
- ✗
Designing the technical security architecture for the organization.
Why it's wrong here
Technical architecture design requires specialist engineering judgement and sits with security architects and IT management, not directors. The board approves the security strategy and risk tolerance that architecture must satisfy. Directors would design architecture only in a tiny firm with no technical staff.
- ✓
Holding executive management accountable for the effectiveness of the security program.
Why this is correct
Accountability sits with the board: it must hold executive management answerable for whether the security programme actually works, typically through reporting and oversight. This satisfies the stem's governance constraint by separating oversight from the day-to-day execution management performs.
- ✗
Conducting internal security audits of the information systems.
Why it's wrong here
Internal audits are performed by an independent audit function reporting to the audit committee, preserving objectivity from those who designed the controls. The board commissions and receives audit results rather than executing testing. Direct board auditing applies only where no separate assurance function exists.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.