CISM - Information Security Governance - Section 1.3

Define organisational structures, roles and responsibilities that support effective information security governance.

Define the roles of the CISO, steering committee, and security teams, and articulate clear lines of accountability for information security decisions. Apply segregation of duties to prevent conflicts of interest and ensure that oversight and execution functions remain independent.

CISO roleSteering committeeSegregation of dutiesAccountability

Practice question for this objective

Free sampleInformation Security Governancemedium

An organisation is forming an information security steering committee to direct its security programme. The information security manager is advising on who should sit on it so that the committee can fulfil its governance role. Which membership profile is most appropriate?

  • ASecurity analysts and engineers who operate the day-to-day controls, so that decisions rest on the deepest available technical detail.
  • BThe information security manager plus external consultants, so that the committee stays free of internal business bias when setting direction.
  • CInternal audit and compliance officers, so that the committee can independently verify that controls already meet regulatory obligations.
  • DSenior leaders from major business units alongside key support functions, so that security decisions reflect enterprise priorities and shared ownership. Correct
A security steering committee should comprise senior business and support leaders so it can align security with enterprise priorities and commit resources. The steering committee exists to set direction and allocate resources for security in line with business strategy. Only senior leaders across business units carry the authority and ownership to make those commitments, whereas operational, advisory or assurance roles cannot direct the enterprise.

Why A is wrong: Tempting because technical depth seems valuable, but operational staff lack the authority to set direction and bind business units to enterprise-level decisions.

Why B is wrong: Tempting as a route to objectivity, but excluding business leaders strips the committee of the authority and ownership needed to govern effectively.

Why C is wrong: Tempting because assurance matters, but audit and compliance provide oversight, not direction, and their independence is compromised if they set the strategy they later review.

Why D is correct: A cross-functional group of business leaders lets the committee align security with business goals and commit resources, which is its intended governance purpose.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.