Home › Certifications › CISM › Information Security Governance
68 multiple-choice questions and 31 flashcards on Information Security Governance, about 17% of the CISM bank. Every one carries a written rationale.
Information Security Governance is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 68 of the bank's 400 multiple-choice questions — roughly 17% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
The board asks whether the enterprise is "secure enough". The MOST appropriate response from the CISO is to:
Answer: A — present current exposure relative to the risk appetite the board has approved
A) Correct — "secure enough" is a question about appetite, and only the board can define enough; the CISO reports position against that agreed line. B) A maturity score answers a different question and imports another organisation's definition of sufficiency. C) Regulatory compliance is a floor and demonstrably does not equate to adequate security. D) Penetration test results are a point-in-time technical sample of a narrow scope.
An enterprise is planning certification to ISO/IEC 27001:2022. Which statement about the standard is accurate?
Answer: A — Annex A contains 93 controls organised into four control themes
A) Correct — the 2022 edition restructured Annex A into 93 controls across organizational, people, physical and technological themes. B) That is the superseded 2013 structure; the transition period closed in October 2025, so no live certificate rests on it. C) Annex A is a reference set tested for applicability through the Statement of Applicability; controls may be excluded with justification. D) Certification is against the management system clauses, with Annex A used as a control reference.
How should regulatory compliance be positioned within the information security strategy?
Answer: E — As a necessary baseline that is not sufficient, with risk-based decisions extending beyond it
E is the position ISACA expects: obligations must be met, but a program built only to satisfy them inherits the regulator's scope and timing rather than the enterprise's own risk profile. A treats a legal duty as discretionary. B is the classic error, since attackers do not confine themselves to a compliance scope. C ignores that control sets lag emerging threats and are deliberately generic. D reverses the relationship, because compliance requirements are an input to risk management, not a substitute for it.
Which is the PRIMARY purpose of an information security strategy?
Answer: E — Align security objectives, programs and investment with business goals and the board's risk appetite
E states the controlling principle: strategy exists to connect security objectives, programs and spend to business goals and the approved risk appetite, and to translate that into fundable initiatives. A is attractive because baselines are real strategy outputs, but configuration detail belongs in standards, not in a board-level direction document. B tempts because eliminating risk sounds like the security mission, yet zero risk is neither achievable nor economically defensible against appetite. C confuses input with outcome; budget growth is not a strategic objective. D inverts the hierarchy: security strategy is subordinate to, and derived from, business strategy.
A security strategy has been drafted but repeatedly fails to secure funding. The MOST likely underlying cause is that the strategy:
Answer: A — lacks a mapping between proposed initiatives and the enterprise's stated objectives
A) Correct — funding follows demonstrated contribution to business objectives; without that linkage the strategy competes on faith against initiatives that can show it. B) Maturity benchmarking strengthens a case but rarely decides it; a high-maturity target with no business rationale still loses. C) Architecture detail is what a funding committee is least equipped to evaluate and does not answer the value question. D) Scheduling matters for execution, but a well-sequenced plan for the wrong outcomes still fails at approval.
Which arrangement BEST prevents information security governance from becoming a purely IT concern?
Answer: D — Making business process owners accountable for the risk in their own processes
D) Correct — assigning risk accountability to process owners places the decisions with the business, which is the structural change that stops security being treated as an IT service. A) Publication improves visibility without transferring any accountability. B) Board presentations improve reporting but leave ownership with the CISO. C) Secondments build mutual understanding and are a useful supporting measure, not a governance mechanism.
An organisation adopts the NIST Cybersecurity Framework 2.0. The PRIMARY value to governance is that it:
Answer: B — Supplies a risk-based vocabulary, including the GOVERN function, for board reporting
B is the governance value: CSF 2.0 gives executives and the board a common, risk-based language for describing current posture, target profile and the gap between them, and its GOVERN function, added in the 2024 revision alongside the original five, makes oversight and risk-strategy expectations explicit. CSF 2.0 also dropped the earlier critical-infrastructure scoping, so it applies to any organisation. A is wrong because a profile is not a policy set. C misreads a voluntary framework as a certification scheme. D is the compliance-guarantee fallacy: no framework confers regulatory compliance.
A subsidiary operates with materially different security practices than the parent. The PRIMARY governance concern is:
Answer: B — Consolidated risk reporting and uniform accountability across the group are undermined
B is the governance-level concern: divergent practice means enterprise risk cannot be aggregated reliably and no single accountability model holds, so the board is briefed on a picture it cannot trust. A is a change-management symptom. C and D are real and worth managing, but they are operational consequences of the same underlying gap. Selecting an operational symptom over the enterprise accountability frame is the standard trap in this item.
A newly appointed CISO is asked by the board to justify the information security programme. The MOST effective way to frame the justification is to:
Answer: B — show how the programme supports board-approved enterprise objectives
B) Correct — governance-first framing ties security investment to the enterprise objectives the board already owns; that is the only language in which a board can weigh value. A) Activity counts feel concrete but signal effort, not business outcome, and invite the question "so what?". C) Peer benchmarking is a useful supporting datapoint but sets someone else's spend as the objective rather than the enterprise's own goals. D) A control inventory is an operational report; it evidences work performed without connecting to why the enterprise funds it.
How do policies, standards, procedures and guidelines relate to one another?
Answer: D — Policy sets mandatory intent, standards set mandatory specifics, procedures how, guidelines advise
D states the cascade and, critically, which tiers are binding: policies and standards are mandatory, procedures describe execution, and guidelines are recommended practice. A erases distinctions the exam tests directly. B inverts the hierarchy by putting execution above intent. C collapses durable direction and volatile detail into one document that then cannot be maintained. E reverses the mandatory and advisory tiers.
4 cards from the 31 in this chapter.
What are the CPE requirements to maintain CISM certification?
A minimum of 20 CPE hours per year and 120 CPE hours over the 3-year reporting cycle, together with payment of the annual maintenance fee and adherence to the CPE policy and Code of Professional Ethics. Falling below the annual 20 breaches the policy even if the 3-year total would otherwise be met.
How many questions does the CISM exam contain, how long is the sitting, and what score is required to pass?
150 multiple-choice questions (scored plus unscored pretest items) in 4 hours. Scoring is a scaled score on a 200-800 range with 450 required to pass. 450 is a scaled value, not 75% of items correct.
Board of directors role?
Sets strategy, oversees risk, ensures regulatory compliance.
ISMS?
Information Security Management System. Framework like ISO 27001.
These are a sample. The full Information Security Governance chapter runs 99 items with per-chapter progress tracking, on the web and in the iOS app.