Greatest Concern for Information Security Governance Effectiveness

Information Security Governance
Answer Correct answer: C — Executive management must formally review the information security policy to establish strategic alignment and enforce organizational accountability.

Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization's information security governance?

  1. Risk assessments of information assets are not periodically performed.
  2. There is no process to measure information security performance.
  3. The information security policy is not reviewed by executive management. Correct Answer
  4. The information security policy does not extend to service providers.

Community Votes

A
75%
C
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between governance oversight and operational risk management, where candidates often mistakenly prioritize risk assessments over executive policy endorsement.

Evaluating information security governance requires verifying executive oversight and policy endorsement rather than focusing solely on operational risk processes. This page clarifies why executive management review is the definitive indicator of effective governance.

Option A is frequently chosen because risk assessments are critical for security operations, but they fall under management responsibilities rather than executive governance.

Community Discussion (3 comments)

46080f2 👍 1 Selected: A
CISA manual 28th ed explicitly states, "Of all the steps listed, performing a risk assessment is the most critical. Risk assessment is required by ISACA IS Audit and Assurance Standard (Risk Assessment in Planning), statement: “IT audit and assurance practitioners shall identify and assess risk relevant to the area under review when planning individual engagements.” In addition to the standards requirement, if a risk assessment is not performed, then high-risk areas of the auditee systems or operations may not be identified for evaluation."
PurpleParrot 👍 2 Selected: A
A. Risk assessments of information assets are not periodically performed. This option is of utmost concern because regular risk assessments are fundamental to identifying, evaluating, and mitigating risks associated with information assets. Without periodic risk assessments, the organization may remain unaware of potential vulnerabilities and threats, leading to inadequate protection of sensitive information and increased exposure to security incidents. While both the lack of periodic risk assessments and the absence of executive review of the information security policy are serious concerns, the priority can depend on the specific context and maturity of the organization's governance. However, your emphasis on the necessity of risk assessments highlights a critical aspect of effective information security governance. Both factors should be taken seriously to ensure comprehensive security management.
Vima234 👍 1 Selected: C
he absence of an information security policy would be of greatest concern because: Governance can't function effectively without clear guidelines and principles. There's no formalized standard for addressing the risks identified by risk assessments. The organization's security posture lacks direction, potentially leading to inconsistent risk management. Thus, in the scenario you presented, the absence of an information security policy would indeed undermine the entire governance process, making it the greatest concern for an IS auditor assessing the effectiveness of governance.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Information security governance fundamentally requires executive oversight and strategic direction rather than operational execution. When the information security policy lacks formal review by executive management, the organization loses authoritative accountability and strategic alignment. ISACA’s governance framework explicitly mandates that leadership must endorse security policies to ensure they reflect business objectives and carry organizational weight. Consequently, auditing governance effectiveness prioritizes executive engagement over routine management activities.

Why the Other Options Are Wrong

Option A describes a critical operational control, but risk assessment belongs to risk management rather than governance oversight. Option B focuses on performance measurement, which falls under continuous monitoring and management reporting instead of high-level governance. Option D addresses policy scope and vendor management, which are important tactical details but do not impact the overarching governance structure. Each distractor confuses management responsibilities with the executive accountability required for true governance.

Community Comment Notes

Learners frequently debate whether risk assessments or executive policy review carries greater weight. Some users cite ISACA documentation to argue that risk assessment is the most critical step, echoing the exact phrase "performing a risk assessment is the most critical" found in top-rated community feedback. Others emphasize that governance cannot function without clear executive guidelines, noting that absent policy reviews leave security efforts directionless. While both perspectives highlight valuable security practices, the examination doctrine strictly separates governance oversight from operational risk cycles. The consensus ultimately aligns with executive endorsement as the primary governance indicator.

Exam Strategy

Always distinguish between governance (executive/board oversight and policy endorsement) and management (operational execution and risk mitigation). When a question asks about governance effectiveness, prioritize answers that demonstrate strategic alignment, leadership accountability, and formal policy approval over technical or procedural controls.

Frequently Asked Questions

Why is risk assessment not the greatest concern for governance?

Risk assessment is an operational management activity focused on identifying vulnerabilities. Governance requires executive oversight, policy approval, and strategic direction.

Does executive policy review replace regular risk assessments?

No. Both are necessary, but governance evaluates leadership accountability first. Risk assessments continue regardless of how they are categorized.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide