CISM - Information Security Governance (17% of the exam) - Section 1.1

Understand organisational culture and its influence on information security governance.

Recognise how an organisation's shared values, norms, and leadership behaviours shape the willingness of staff to comply with and champion information security. Distinguish between a culture where security is enforced from the top and one where it is embedded through demonstrated executive commitment and tone at the top.

Organisational cultureSecurity cultureTone at the top

Practice question for this objective

Free sampleInformation Security Governancemedium

A newly appointed information security manager finds that staff routinely share login credentials and bypass access controls, even though a detailed acceptable-use policy exists and is technically sound. Senior executives openly describe these controls as obstacles to getting work done. Which factor is MOST likely the root cause of the weak security behaviour?

  • AThe acceptable-use policy lacks sufficient technical detail on credential management procedures.
  • BThe tone at the top signals that security is a hindrance, shaping a culture in which non-compliance is normalised. Correct
  • CEmployees have not yet completed the annual security awareness training module on password hygiene.
  • DThe access control technology is misconfigured and permits credential sharing without detection.
Recognise that leadership tone at the top is the primary driver of an organisation's prevailing security culture and behaviour. Security culture is shaped most strongly by the attitudes and behaviours that leaders model and reward. When executives frame controls as obstacles, employees infer that non-compliance is acceptable, so behaviour follows the cultural signal rather than the written policy or the technology in place.

Why A is wrong: Tempting because policy gaps are a common finding, but the scenario states the policy is detailed and technically sound, so additional detail would not change behaviour driven by leadership attitude.

Why B is correct: Correct because when senior leadership visibly treats controls as obstacles, employees model that attitude, and this leadership-set tone is the dominant influence on the prevailing security culture and behaviour.

Why C is wrong: Tempting because awareness gaps do drive poor habits, but training cannot overcome a culture in which leadership openly devalues controls, so the absence of training is a symptom rather than the root cause.

Why D is wrong: Tempting because technical weaknesses can enable bad behaviour, but the issue described is a deliberate choice to bypass working controls, which points to culture and leadership rather than a configuration fault.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Senior leaders approve the detailed technical configuration baselines, ensuring that protecting information is enforced consistently on every production system in the estate.

    Why it is wrong: Tempting because leadership endorsement matters, but approving technical baselines is an operational control task, not the cultural signalling that tone at the top describes.

  • The percentage of servers patched within the agreed remediation window each month.

    Why it is wrong: Tempting because patch timeliness is a respected operational metric, but it measures technical control performance and not how people think about or act on security.

  • Agree that the security team owns culture, and propose increasing the frequency of mandatory training to accelerate change.

    Why it is wrong: Tempting because it accepts the director's framing and offers a concrete action, but it wrongly confines culture ownership to one team and overstates training as the primary lever.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.