CISM - Information Security Governance (17% of the exam) - Section 1.5

Apply information governance frameworks and standards to guide the security programme.

Apply governance frameworks such as COBIT, ISO/IEC 27001, and the NIST CSF to structure and guide the information security programme. Compare these frameworks to determine which best fits the organisation's regulatory environment, maturity level, and governance objectives.

COBITISO/IEC 27001NIST CSFGovernance frameworks

Practice question for this objective

Free sampleInformation Security Governancemedium

A manufacturing group has adopted ISO/IEC 27001 for its certified information security management system, but the board now wants assurance that security investment decisions, accountability, and benefits realisation align with wider enterprise IT governance. The information security manager is asked which framework best complements the existing standard to address that specific gap. Which choice is most appropriate?

  • AAdopt COBIT to provide enterprise governance and management objectives that connect security to business value and accountability. Correct
  • BReplace ISO/IEC 27001 with the NIST Cybersecurity Framework to obtain a governance-led structure for the whole programme.
  • CImplement ISO/IEC 27002 so the organisation has a richer catalogue of controls to satisfy the board's request.
  • DMap the ISMS to ISO/IEC 27004 so security metrics demonstrate governance to the board.
Recognise that COBIT supplies enterprise governance linkage that a certified ISMS standard such as ISO/IEC 27001 does not by itself provide. COBIT separates governance from management and ties security and IT objectives to stakeholder value, accountability, and benefits realisation, complementing an ISMS that focuses on operating security controls rather than enterprise governance.

Why A is correct: COBIT is a governance and management framework that links IT and security activities to enterprise objectives, value delivery, and clear accountability, which is exactly the assurance the board is seeking.

Why B is wrong: The NIST CSF does include a Govern function, which makes this tempting, but it is a voluntary control and outcome framework rather than an enterprise IT governance model, and discarding a certified ISMS to gain governance is disproportionate and unnecessary.

Why C is wrong: ISO/IEC 27002 expands control guidance, which sounds helpful, but the board asked about investment decisions, accountability, and benefits realisation, which are governance concerns that a control catalogue does not address.

Why D is wrong: ISO/IEC 27004 covers measurement of information security performance, which is useful for reporting, but measurement alone does not establish the value, accountability, and decision rights that enterprise governance requires.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • ISO/IEC 27005, because it provides detailed implementation guidance for the individual security controls that the Statement of Applicability lists

    Why it is wrong: Tempting as a sibling standard, but 27005 covers information security risk management, not control-level implementation guidance.

  • ISO/IEC 27001, because its management-system clauses define enterprise IT governance roles, value delivery and benefits realisation across all of IT

    Why it is wrong: Tempting since 27001 is a governance-adjacent standard, but its scope is the information security management system, not enterprise-wide IT governance and value delivery.

  • ISO/IEC 27002, because it supplies an outcome-based set of functions that a board can use to discuss the organisation's overall risk posture

    Why it is wrong: Tempting as the companion to 27001, but 27002 is detailed control implementation guidance, not an outcome-function model for board-level posture discussion.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.