Executive Role in Security Governance

Information Security Governance
Answer Correct answer: A — reviewing the information security policy directing the organization.

When an organization implements an information security governance framework, it is MOST important for executive leadership to have a direct role in:

  1. reviewing the information security policy directing the organization. Correct Answer
  2. developing technical key risk indicators (KRIs) for information security.
  3. implementing information security metrics for the organization.
  4. approving information security standards and procedures for the organization.

Community Votes

A
67%
D
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between policy and standards, where the common trap is assuming executives approve low-level implementation documents like standards.

In information security governance, executive leadership must primarily ensure high-level alignment, making the review and direction of the information security policy their most critical responsibility.

Many candidates choose Option D because executives typically 'approve' documents, but they fail to recognize that standards and procedures are operational details, not high-level governance instruments.

Community Discussion (4 comments)

david124 👍 1 Selected: A
idk guys looks like A
Raj91188 👍 3 Selected: A
It's clearly A, not D. Executives do not approve standards and procedures, they are low level documents, Executives approve Security policy.
pgonza 👍 2 Selected: D
Executive (board) will only approve
Booict 👍 4
D - approving information security standards and procedures for the organization”. While direct review by executives may not occur, their approval ensures alignment with organizational goals, risk management, and compliance. This is according to according to CISM principles. Not sure why the answer is A.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because information security governance relies on the "tone at the top." Executive leadership is responsible for ensuring the security policy aligns with business objectives and risk appetite. By reviewing the policy, they provide the necessary authority and direction for the entire program.

Why the Other Options Are Wrong

Option B is incorrect because developing technical Key Risk Indicators (KRIs) is a managerial or operational task, not an executive function. Option C is incorrect because implementing metrics is an operational activity. Option D is incorrect because approving standards and procedures is generally delegated to middle management or security architects; these are too granular for executive review.

Community Comment Notes

Community members correctly identified that executives focus on high-level policy rather than detailed standards. One user emphasized that standards are "low level documents," reinforcing the governance hierarchy where executives own the policy, not the technical implementation details.

Official Reference

Exam Strategy

Remember the governance hierarchy: Policy (Executives) -> Standards (Management) -> Procedures (Staff). Focus on the "tone at the top" concept for governance questions.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide