CISSP - Security and Risk Management (16% of the exam) - Section 1.3

Evaluate and apply security governance principles aligned with organisational goals, mission, and strategy.

Describe how governance frameworks align security strategy with organisational mission, goals, and due diligence obligations. Choose the appropriate security control framework for a given organisational context and explain how governance structures assign accountability.

governance frameworksorganisational alignmentdue diligencesecurity control frameworks

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A newly appointed CISO at a mid-sized manufacturing firm finds that the information security programme has historically been driven entirely by the IT department, with controls selected by engineers based on technical merit. The board has asked the CISO to demonstrate that security investment is aligned with the business. Which action should the CISO take FIRST to establish governance alignment?

  • AEngage with executive leadership to identify business objectives, risk appetite, and critical assets before defining a security strategy. Correct
  • BAdopt the NIST Cybersecurity Framework and map all existing technical controls to its categories to show coverage.
  • CCommission an external penetration test to baseline the current technical posture and report findings to the board.
  • DRestructure the security team to report directly to the CEO and publish an updated information security policy.
Security governance alignment starts with understanding business mission, objectives, and risk appetite before selecting frameworks or controls. CISSP treats security governance as the translation of organisational goals into a security strategy. Without first eliciting mission, objectives, and risk appetite from senior leadership, any framework adoption or control selection risks defending the wrong things or constraining the business. The strategy is the artefact that ties leadership intent to subsequent control selection.

Why A is correct: Governance alignment begins by understanding mission, objectives, and risk appetite from senior leadership; only then can the security strategy be shaped to support, rather than constrain, the business.

Why B is wrong: Mapping controls to a framework is useful but it documents what already exists rather than confirming the programme supports the business mission, so it answers the wrong question first.

Why C is wrong: A penetration test produces a technical snapshot but does not address the governance gap the board raised; tactical findings without strategic context perpetuate the IT-led problem.

Why D is wrong: Reporting line changes and a fresh policy are reasonable later actions, but they will lack credibility until the CISO can show the strategy reflects what leadership actually values.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Deploy the acquirer's endpoint protection agents across the target's workstations to gain visibility into any active threats.

    Why it is wrong: Pushing agents into a company that has not yet been acquired oversteps authority and would not be permitted; due diligence precedes, rather than replaces, integration activity.

  • Adopt PCI DSS as the primary framework because cardholder data carries the most prescriptive technical requirements.

    Why it is wrong: PCI DSS is highly prescriptive but scoped only to cardholder data environments, so it cannot serve as the enterprise-wide management system the organisation needs for its wider obligations.

  • Pseudonymise the records before export and treat the transferred data as anonymised so GDPR no longer applies to the Virginia warehouse.

    Why it is wrong: Pseudonymisation alone does not strip personal data of GDPR scope because the controller still holds the keys and re-identification remains feasible; the transfer is still a restricted transfer requiring a lawful mechanism.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.