mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: Is developing a security governance framework to…
An organization is developing a security governance framework to align with business objectives. Which group should have ultimate authority and responsibility for the cybersecurity program?
⚠ Common exam trap
CISSP often tests the distinction between operational responsibility (CISO, CEO) and ultimate governance authority (board of directors), tricking candidates into selecting the CISO as the answer because they are the most visible security leader.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Board of directors
The board of directors holds ultimate fiduciary duty for the organization, including oversight of risk management and cybersecurity. They approve the security governance framework and ensure it aligns with business objectives, as they are legally accountable for the entire enterprise. The CISO and CEO implement the program, but the board retains final authority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT steering committee
Why it's wrong here
An IT steering committee typically provides guidance and oversight for IT projects and operational initiatives, ensuring alignment with business objectives. While crucial for tactical decision-making and resource allocation within the IT domain, it operates at a management or advisory level, lacking the ultimate legal and fiduciary responsibility for enterprise-wide risk management and governance. Therefore, it does not possess the authority to establish the foundational security governance framework for the entire organization.
- ✓
Board of directors
Why this is correct
The Board of Directors holds the ultimate fiduciary responsibility for the organization's overall governance, risk management, and compliance, including cybersecurity. They are legally accountable to shareholders and stakeholders for ensuring that adequate controls and strategies are in place to protect assets and manage enterprise risks effectively. Establishing the security governance framework is a strategic imperative that falls squarely within their purview, setting the tone at the top and delegating authority appropriately.
- ✗
Chief Information Security Officer (CISO)
Why it's wrong here
The Chief Information Security Officer (CISO) is responsible for developing, implementing, and managing the organization's information security program and strategy. While the CISO leads the security function, advises executive leadership on security risks, and ensures compliance with established policies, their role is primarily operational and tactical within the framework established by higher authority. The CISO does not possess the ultimate governance authority or fiduciary duty to establish the overarching security governance framework itself.
- ✗
Chief Executive Officer (CEO)
Why it's wrong here
The Chief Executive Officer (CEO) is responsible for the overall operational management and strategic execution of the organization, reporting directly to the Board of Directors. While the CEO is accountable for the organization's performance and ensures that security initiatives are funded and supported, the ultimate responsibility for establishing the foundational governance framework, including enterprise risk management and cybersecurity oversight, rests with the Board. The CEO executes the strategy and manages the business within the governance parameters set by the Board.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security governance
Security governance is the framework of rules, policies, and processes that an organization uses to align its cybersecurity activities with its business goals and legal obligations.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.