Courseiva
easyMultiple Select

CISM Practice Question: Which TWO of the following are typically…

Which TWO of the following are typically considered key components of an information security governance framework?

⚠ Common exam trap

CISM often tests the governance-versus-management distinction, and the trap is selecting operational activities (pen tests, IR plans, technical controls) that feel security-related but are not governance framework components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adoption of a formal risk management process

Option A (adoption of a formal risk management process) is correct because governance frameworks such as ISO/IEC 27001 and COBIT require an ongoing, structured risk management process to identify, assess, treat, and monitor information security risks, providing the decision-making foundation that governance bodies use to align security with business objectives. Option C (establishment of a performance measurement system) is correct because governance depends on metrics, KPIs, and reporting mechanisms (e.g., COBIT's performance management domain) to monitor whether security controls and objectives are effective and to hold management accountable. The unmarked options do not belong because scheduling regular penetration tests (B), developing a detailed incident response plan (D), and implementing specific technical controls (E) are operational, tactical activities executed under the governance framework rather than components of the governance framework itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adoption of a formal risk management process

    Why this is correct

    A formal risk management process identifies, assesses and treats information risk in line with the organisation's risk appetite, directing security investment and control selection. It is a core governance component because it links security decisions to business risk.

  • ✗

    Scheduling of regular penetration tests

    Why it's wrong here

    Penetration testing is an assurance activity executed under governance, not a structural component of the framework itself. It is tempting because testing frequency and scope are mandated by governance, and scheduling regular tests is a valid control activity once policies, roles and oversight structures already exist.

  • ✓

    Establishment of a performance measurement system

    Why this is correct

    A performance measurement system supplies the metrics that let governance bodies verify controls operate as intended and align with business objectives. Without measurable indicators, the framework cannot demonstrate effectiveness or drive accountability, so this component satisfies the stem's requirement for a key governance element.

  • ✗

    Development of a detailed incident response plan

    Why it's wrong here

    An incident response plan is an operational capability sitting beneath governance, not one of its components. It is tempting because governance requires incident handling to be defined and reviewed, so a detailed plan is a natural deliverable once strategy, risk appetite and accountability structures are established.

  • ✗

    Implementation of specific technical controls

    Why it's wrong here

    Individual technical controls are implemented as a consequence of governance direction, not as a component of the framework. It is tempting because governance must ensure controls exist and are effective, so selecting and deploying specific controls is the correct activity once policies, roles and monitoring structures are in place.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.