CISM - Information Security Governance - Section 1.1

Understand organisational culture and its influence on information security governance.

Recognise how an organisation's shared values, norms, and leadership behaviours shape the willingness of staff to comply with and champion information security. Distinguish between a culture where security is enforced from the top and one where it is embedded through demonstrated executive commitment and tone at the top.

Organisational cultureSecurity cultureTone at the top

Practice question for this objective

Free sampleInformation Security Governancemedium

A newly appointed information security manager finds that staff routinely share login credentials and bypass access controls, even though a detailed acceptable-use policy exists and is technically sound. Senior executives openly describe these controls as obstacles to getting work done. Which factor is MOST likely the root cause of the weak security behaviour?

  • AThe acceptable-use policy lacks sufficient technical detail on credential management procedures.
  • BThe tone at the top signals that security is a hindrance, shaping a culture in which non-compliance is normalised. Correct
  • CEmployees have not yet completed the annual security awareness training module on password hygiene.
  • DThe access control technology is misconfigured and permits credential sharing without detection.
Recognise that leadership tone at the top is the primary driver of an organisation's prevailing security culture and behaviour. Security culture is shaped most strongly by the attitudes and behaviours that leaders model and reward. When executives frame controls as obstacles, employees infer that non-compliance is acceptable, so behaviour follows the cultural signal rather than the written policy or the technology in place.

Why A is wrong: Tempting because policy gaps are a common finding, but the scenario states the policy is detailed and technically sound, so additional detail would not change behaviour driven by leadership attitude.

Why B is correct: Correct because when senior leadership visibly treats controls as obstacles, employees model that attitude, and this leadership-set tone is the dominant influence on the prevailing security culture and behaviour.

Why C is wrong: Tempting because awareness gaps do drive poor habits, but training cannot overcome a culture in which leadership openly devalues controls, so the absence of training is a symptom rather than the root cause.

Why D is wrong: Tempting because technical weaknesses can enable bad behaviour, but the issue described is a deliberate choice to bypass working controls, which points to culture and leadership rather than a configuration fault.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.