Best Indicator of Integrating Information Security Governance with Corporate Governance

Answer Correct answer: D — Security performance metrics are measured against business objectives.

Which of the following is the BEST indication that an organization has integrated information security governance with corporate governance?

  1. Impact is measured according to business loss when assessing IT risk.
  2. Service levels for security vendors are defined according to business needs.
  3. Security policies are reviewed whenever business objectives are changed.
  4. Security performance metrics are measured against business objectives. Correct Answer

Community Votes

D
60%
C
40%

60% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to distinguish strategic governance alignment from operational policy updates, where candidates often mistakenly choose policy review triggers over performance metric alignment.

Aligning information security metrics with corporate business objectives is the strongest evidence of effective security governance integration, as confirmed by CISM exam candidates and expert analysis.

Option C is frequently selected because candidates equate policy reviews with governance, but policy maintenance is a tactical control rather than a strategic governance indicator.

Community Discussion (5 comments)

david124 👍 1 Selected: D
ima go with D one this one, it says review policy not change or revise for c
ServerBrain 👍 1 Selected: C
policies relate to governance.
afoo1314 👍 3 Selected: D
Security policies don't change often even with business objective change. Business objectives always priority.
sausageman 👍 2 Selected: D
D. Security performance metrics are measured against business objectives. Seems right for me
yottabyte 👍 3 Selected: C
C seems to be apt here.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Corporate governance fundamentally requires measurable alignment between security initiatives and enterprise goals. Measuring security performance metrics against business objectives demonstrates that leadership tracks security outcomes through the same financial and operational lenses used for overall corporate success. This direct linkage transforms security from an isolated technical function into a strategic business enabler.

Why the Other Options Are Wrong

Option A focuses on IT risk impact measurement, which belongs to risk assessment rather than overarching governance integration. Option B addresses vendor service level agreements, which are operational procurement details unrelated to strategic board-level oversight. Option C suggests policy reviews during objective changes, but policy updates are reactive administrative tasks that lack the continuous performance tracking required for true governance maturity.

Community Comment Notes

Candidates consistently highlight why option D outweighs option C, noting that security policies rarely require immediate revision even when business objectives shift. Multiple voters emphasize that governance demands proactive measurement rather than reactive documentation adjustments. As noted in top-rated discussions, tracking performance against strategic targets provides the executive visibility necessary for sustained governance integration.

Official Reference

Exam Strategy

Focus on strategic alignment over tactical execution when answering governance questions; always prioritize options that link security outcomes directly to enterprise value and business objectives. Eliminate choices describing day-to-day operations, vendor contracts, or static documentation updates.

Frequently Asked Questions

Why isn't reviewing security policies when business objectives change the best indicator?

Policy reviews are tactical compliance activities. Strategic governance requires measurable outcomes tied directly to business value.

How do I distinguish security governance from risk management in CISM exams?

Governance focuses on strategic alignment and performance measurement against business goals, while risk management handles threat assessment and mitigation controls.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide