Executive Role in Security Governance
When an organization implements an information security governance framework, it is MOST important for executive leadership to have a direct role in:
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between policy and standards, where the common trap is assuming executives approve low-level implementation documents like standards.
In information security governance, executive leadership must primarily ensure high-level alignment, making the review and direction of the information security policy their most critical responsibility.
Many candidates choose Option D because executives typically 'approve' documents, but they fail to recognize that standards and procedures are operational details, not high-level governance instruments.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because information security governance relies on the "tone at the top." Executive leadership is responsible for ensuring the security policy aligns with business objectives and risk appetite. By reviewing the policy, they provide the necessary authority and direction for the entire program.Why the Other Options Are Wrong
Option B is incorrect because developing technical Key Risk Indicators (KRIs) is a managerial or operational task, not an executive function. Option C is incorrect because implementing metrics is an operational activity. Option D is incorrect because approving standards and procedures is generally delegated to middle management or security architects; these are too granular for executive review.Community Comment Notes
Community members correctly identified that executives focus on high-level policy rather than detailed standards. One user emphasized that standards are "low level documents," reinforcing the governance hierarchy where executives own the policy, not the technical implementation details.Official Reference
Exam Strategy
Remember the governance hierarchy: Policy (Executives) -> Standards (Management) -> Procedures (Staff). Focus on the "tone at the top" concept for governance questions.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →