CISM - Information Security Governance (17% of the exam) - Section 1.3

Define organisational structures, roles and responsibilities that support effective information security governance.

Define the roles of the CISO, steering committee, and security teams, and articulate clear lines of accountability for information security decisions. Apply segregation of duties to prevent conflicts of interest and ensure that oversight and execution functions remain independent.

CISO roleSteering committeeSegregation of dutiesAccountability

Practice question for this objective

Free sampleInformation Security Governancemedium

An organisation is forming an information security steering committee to direct its security programme. The information security manager is advising on who should sit on it so that the committee can fulfil its governance role. Which membership profile is most appropriate?

  • ASecurity analysts and engineers who operate the day-to-day controls, so that decisions rest on the deepest available technical detail.
  • BThe information security manager plus external consultants, so that the committee stays free of internal business bias when setting direction.
  • CInternal audit and compliance officers, so that the committee can independently verify that controls already meet regulatory obligations.
  • DSenior leaders from major business units alongside key support functions, so that security decisions reflect enterprise priorities and shared ownership. Correct
A security steering committee should comprise senior business and support leaders so it can align security with enterprise priorities and commit resources. The steering committee exists to set direction and allocate resources for security in line with business strategy. Only senior leaders across business units carry the authority and ownership to make those commitments, whereas operational, advisory or assurance roles cannot direct the enterprise.

Why A is wrong: Tempting because technical depth seems valuable, but operational staff lack the authority to set direction and bind business units to enterprise-level decisions.

Why B is wrong: Tempting as a route to objectivity, but excluding business leaders strips the committee of the authority and ownership needed to govern effectively.

Why C is wrong: Tempting because assurance matters, but audit and compliance provide oversight, not direction, and their independence is compromised if they set the strategy they later review.

Why D is correct: A cross-functional group of business leaders lets the committee align security with business goals and commit resources, which is its intended governance purpose.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • With the CISO, who by accepting the role assumes ultimate accountability for the organisation's information security risk on the board's behalf.

    Why it is wrong: Tempting because the CISO leads security, but the role carries delegated responsibility for execution, not the board's ultimate accountability for risk.

  • The chief information officer, so that security priorities stay closely aligned with day-to-day IT delivery and infrastructure planning.

    Why it is wrong: Reporting to the CIO is a common arrangement and feels efficient, but it subordinates security to the IT delivery agenda and creates a conflict where the function meant to challenge IT risk reports to the executive accountable for IT delivery.

  • It reviews and approves firewall rule changes and patch schedules before the operations team applies them to production systems.

    Why it is wrong: This is tempting because it shows the committee being active, but approving firewall rules and patch schedules is operational work that belongs to technical teams, not the strategic alignment role of a steering committee.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.