easyMultiple Select
CISM Practice Question: Which TWO of the following are typically…
Which TWO of the following are typically considered key components of an information security governance framework?
⚠ Common exam trap
CISM often tests the governance-versus-management distinction, and the trap is selecting operational activities (pen tests, IR plans, technical controls) that feel security-related but are not governance framework components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adoption of a formal risk management process
Option A (adoption of a formal risk management process) is correct because governance frameworks such as ISO/IEC 27001 and COBIT require an ongoing, structured risk management process to identify, assess, treat, and monitor information security risks, providing the decision-making foundation that governance bodies use to align security with business objectives. Option C (establishment of a performance measurement system) is correct because governance depends on metrics, KPIs, and reporting mechanisms (e.g., COBIT's performance management domain) to monitor whether security controls and objectives are effective and to hold management accountable. The unmarked options do not belong because scheduling regular penetration tests (B), developing a detailed incident response plan (D), and implementing specific technical controls (E) are operational, tactical activities executed under the governance framework rather than components of the governance framework itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adoption of a formal risk management process
Why this is correct
A formal risk management process identifies, assesses and treats information risk in line with the organisation's risk appetite, directing security investment and control selection. It is a core governance component because it links security decisions to business risk.
- ✗
Scheduling of regular penetration tests
Why it's wrong here
Penetration testing is an assurance activity executed under governance, not a structural component of the framework itself. It is tempting because testing frequency and scope are mandated by governance, and scheduling regular tests is a valid control activity once policies, roles and oversight structures already exist.
- ✓
Establishment of a performance measurement system
Why this is correct
A performance measurement system supplies the metrics that let governance bodies verify controls operate as intended and align with business objectives. Without measurable indicators, the framework cannot demonstrate effectiveness or drive accountability, so this component satisfies the stem's requirement for a key governance element.
- ✗
Development of a detailed incident response plan
Why it's wrong here
An incident response plan is an operational capability sitting beneath governance, not one of its components. It is tempting because governance requires incident handling to be defined and reviewed, so a detailed plan is a natural deliverable once strategy, risk appetite and accountability structures are established.
- ✗
Implementation of specific technical controls
Why it's wrong here
Individual technical controls are implemented as a consequence of governance direction, not as a component of the framework. It is tempting because governance must ensure controls exist and are effective, so selecting and deploying specific controls is the correct activity once policies, roles and monitoring structures are in place.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.