Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: Is developing a security governance framework to…

An organization is developing a security governance framework to align with business objectives. Which group should have ultimate authority and responsibility for the cybersecurity program?

⚠ Common exam trap

CISSP often tests the distinction between operational responsibility (CISO, CEO) and ultimate governance authority (board of directors), tricking candidates into selecting the CISO as the answer because they are the most visible security leader.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Board of directors

The board of directors holds ultimate fiduciary duty for the organization, including oversight of risk management and cybersecurity. They approve the security governance framework and ensure it aligns with business objectives, as they are legally accountable for the entire enterprise. The CISO and CEO implement the program, but the board retains final authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IT steering committee

    Why it's wrong here

    An IT steering committee typically provides guidance and oversight for IT projects and operational initiatives, ensuring alignment with business objectives. While crucial for tactical decision-making and resource allocation within the IT domain, it operates at a management or advisory level, lacking the ultimate legal and fiduciary responsibility for enterprise-wide risk management and governance. Therefore, it does not possess the authority to establish the foundational security governance framework for the entire organization.

  • Board of directors

    Why this is correct

    The Board of Directors holds the ultimate fiduciary responsibility for the organization's overall governance, risk management, and compliance, including cybersecurity. They are legally accountable to shareholders and stakeholders for ensuring that adequate controls and strategies are in place to protect assets and manage enterprise risks effectively. Establishing the security governance framework is a strategic imperative that falls squarely within their purview, setting the tone at the top and delegating authority appropriately.

  • Chief Information Security Officer (CISO)

    Why it's wrong here

    The Chief Information Security Officer (CISO) is responsible for developing, implementing, and managing the organization's information security program and strategy. While the CISO leads the security function, advises executive leadership on security risks, and ensures compliance with established policies, their role is primarily operational and tactical within the framework established by higher authority. The CISO does not possess the ultimate governance authority or fiduciary duty to establish the overarching security governance framework itself.

  • Chief Executive Officer (CEO)

    Why it's wrong here

    The Chief Executive Officer (CEO) is responsible for the overall operational management and strategic execution of the organization, reporting directly to the Board of Directors. While the CEO is accountable for the organization's performance and ensures that security initiatives are funded and supported, the ultimate responsibility for establishing the foundational governance framework, including enterprise risk management and cybersecurity oversight, rests with the Board. The CEO executes the strategy and manages the business within the governance parameters set by the Board.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.