CISM

Information Security Governance

50 practice questions with explanations — 15 free to try

PassNova has 50 CISM practice questions on Information Security Governance, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Information Security Governance: example questions & answers

3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 50-question Information Security Governance bank is part of PassNova Premium.

  1. An information security manager is establishing a security governance framework. What is the MOST important factor to ensure its success?

    • AAchieving the lowest possible information security budget
    • BSelecting a widely recognised control framework such as ISO 27001
    • CAlignment of the security strategy with business objectives
    • DDeploying advanced technical security controls across the enterprise

    Answer: Effective security governance depends primarily on aligning the security strategy with business objectives so that security supports and enables the organisation's goals.

  2. Who should have ultimate accountability for an organisation's information security governance?

    • AThe information security manager
    • BThe IT operations department
    • CThe board of directors and senior management
    • DThe external security auditor

    Answer: Governance is a leadership responsibility; the board and senior management hold ultimate accountability for direction, oversight, and resourcing of information security.

  3. What is the PRIMARY purpose of an information security strategy?

    • ATo define disciplinary action for policy violations
    • BTo document the technical configuration of every security device deployed on the network
    • CTo provide a roadmap that links security activities to organisational goals
    • DTo list every known threat facing the organisation

    Answer: A security strategy provides a roadmap that connects security initiatives to business goals, guiding investment and prioritisation over time.

Start practising Information Security Governance →