CISM - Information Security Governance - Section 1.5

Apply information governance frameworks and standards to guide the security programme.

Apply governance frameworks such as COBIT, ISO/IEC 27001, and the NIST CSF to structure and guide the information security programme. Compare these frameworks to determine which best fits the organisation's regulatory environment, maturity level, and governance objectives.

COBITISO/IEC 27001NIST CSFGovernance frameworks

Practice question for this objective

Free sampleInformation Security Governancemedium

A manufacturing group has adopted ISO/IEC 27001 for its certified information security management system, but the board now wants assurance that security investment decisions, accountability, and benefits realisation align with wider enterprise IT governance. The information security manager is asked which framework best complements the existing standard to address that specific gap. Which choice is most appropriate?

  • AAdopt COBIT to provide enterprise governance and management objectives that connect security to business value and accountability. Correct
  • BReplace ISO/IEC 27001 with the NIST Cybersecurity Framework to obtain a governance-led structure for the whole programme.
  • CImplement ISO/IEC 27002 so the organisation has a richer catalogue of controls to satisfy the board's request.
  • DMap the ISMS to ISO/IEC 27004 so security metrics demonstrate governance to the board.
Recognise that COBIT supplies enterprise governance linkage that a certified ISMS standard such as ISO/IEC 27001 does not by itself provide. COBIT separates governance from management and ties security and IT objectives to stakeholder value, accountability, and benefits realisation, complementing an ISMS that focuses on operating security controls rather than enterprise governance.

Why A is correct: COBIT is a governance and management framework that links IT and security activities to enterprise objectives, value delivery, and clear accountability, which is exactly the assurance the board is seeking.

Why B is wrong: The NIST CSF does include a Govern function, which makes this tempting, but it is a voluntary control and outcome framework rather than an enterprise IT governance model, and discarding a certified ISMS to gain governance is disproportionate and unnecessary.

Why C is wrong: ISO/IEC 27002 expands control guidance, which sounds helpful, but the board asked about investment decisions, accountability, and benefits realisation, which are governance concerns that a control catalogue does not address.

Why D is wrong: ISO/IEC 27004 covers measurement of information security performance, which is useful for reporting, but measurement alone does not establish the value, accountability, and decision rights that enterprise governance requires.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.