CISM Information Security Governance 1 — Questions and Answers
Question 1: Which of the following BEST describes the primary objective of information security governance?
- Aligning security strategy with business objectives (Correct answer)
- Deploying firewalls and intrusion detection systems
- Training employees on password policies
- Conducting annual penetration tests
Correct answer: Aligning security strategy with business objectives
Information security governance ensures that security strategies are aligned with and support the overall business objectives of the organization.
Question 2: A CISM is developing a security governance framework. Which document should serve as the TOP-LEVEL foundation?
- Security procedures
- Security standards
- Information security policy (Correct answer)
- Risk register
Correct answer: Information security policy
The information security policy is the top-level document that establishes management's intent and provides the foundation for all other security standards and procedures.
Question 3: Which governance structure BEST ensures accountability for information security across the organization?
- Centralized IT helpdesk
- Defined roles and responsibilities with clear ownership (Correct answer)
- Annual security audits by external firms
- Automated vulnerability scanning tools
Correct answer: Defined roles and responsibilities with clear ownership
Clearly defined roles and responsibilities with assigned ownership ensure accountability and enable effective governance across the organization.
Question 4: An organization's board of directors is MOST responsible for which security governance activity?
- Writing security policies
- Setting risk appetite and oversight (Correct answer)
- Conducting vulnerability assessments
- Managing security operations
Correct answer: Setting risk appetite and oversight
The board of directors is responsible for setting the organization's risk appetite and providing oversight of the overall security posture.
Question 5: Which metric BEST demonstrates the effectiveness of an information security governance program to senior leadership?
- Number of firewall rules implemented
- Percentage of employees completing security awareness training
- Ratio of security incidents to business risk tolerance (Correct answer)
- Number of software vulnerabilities patched
Correct answer: Ratio of security incidents to business risk tolerance
Comparing security incidents against defined business risk tolerance gives leadership meaningful insight into how well the governance program is performing relative to strategic objectives.
Question 6: A CISM wants to ensure that information security governance is integrated into organizational decision-making. The BEST approach is to:
- Require IT sign-off on all purchases
- Establish a security steering committee with cross-functional representation (Correct answer)
- Mandate security training for all new hires
- Deploy a SIEM platform organization-wide
Correct answer: Establish a security steering committee with cross-functional representation
A cross-functional security steering committee embeds security governance into broader organizational decision-making processes across business units.
Which of the following BEST describes the primary objective of information security governance?