CISM domain - 17% of the exam

Information Security Governance

Information Security Governance is 17% of the Certified Information Security Manager (CISM) (CISM) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleInformation Security Governancehard

Midway through the financial year, an unforeseen regulatory change forces the information security manager to fund an urgent data-protection project that was not in the approved budget. The annual security budget is already fully committed and the board has frozen requests for additional funds until the next cycle. Which action best reflects sound resource allocation in this situation?

  • ADefer the regulatory project to the next budget cycle and formally document the resulting compliance exposure as an accepted risk.
  • BRe-prioritise the existing portfolio and reallocate funds from lower-risk initiatives to the regulatory project after assessing the impact. Correct
  • CReduce the scope of every active initiative by an equal percentage to free the funds the regulatory project needs.
  • DFund the regulatory project from operational contingency without informing the board until the year-end budget review.
Under a frozen budget, sound resource allocation re-prioritises committed funds toward the highest risk based on an impact assessment. Resource management means continuously steering finite funds toward the greatest risk reduction. Reallocating from lower-risk initiatives, supported by an impact assessment, meets the regulatory obligation without breaching governance, whereas deferral accepts an avoidable breach, equal cuts ignore relative risk, and drawing contingency in secret bypasses board oversight.

Why A is wrong: Tempting because it respects the funding freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship and the manager rarely has authority to accept that level of risk alone.

Why B is correct: Correct because re-prioritising within the committed budget directs scarce resources to the highest-risk obligation while a documented impact assessment keeps the deferred work visible, which is disciplined resource management under constraint.

Why C is wrong: Tempting because spreading the cut feels even-handed, but uniform reductions ignore the relative risk of each initiative and can weaken high-value controls, which is the opposite of risk-based allocation.

Why D is wrong: Tempting because contingency exists for surprises, but quietly drawing it down and bypassing governance for a material regulatory matter breaches transparency and undermines the board's oversight of the budget.

Other domains in this exam

See also the CISM cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.