Free Certified Information Security Manager practice — 6 questions on Information Security Governance, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 1: Information Security Governance
A CISO must select one metric to present to the board that best demonstrates whether the security program is achieving its governance objective. Which metric is MOST appropriate?
Governance reporting to the board must translate operational activity into business terms — whether risk is being managed within the tolerance the board itself set. Residual risk trend against risk appetite directly answers the governance question 'are we operating within acceptable risk?' and ties security performance to enterprise decision-making.
Question 2 of 6 · Domain 1: Information Security Governance
A global enterprise has fully decentralized security teams within each business unit, resulting in inconsistent policy enforcement and duplicated risk decisions across the organization. The CISM candidate is asked to recommend a governance structure that resolves this without eliminating business unit responsiveness. Which structure is BEST?
A federated governance model preserves business unit agility and local implementation authority while enforcing enterprise-wide consistency in policy, standards, and risk tolerance, with a formal escalation path — this is the standard ISACA-recommended resolution when full centralization would harm business responsiveness but pure decentralization causes inconsistency.
Question 3 of 6 · Domain 1: Information Security Governance
Multiple stakeholders — legal, enterprise risk, IT, and business unit leaders — must all provide input before the security strategy can be finalized and aligned to enterprise objectives. Which governance structure BEST ensures this alignment occurs formally and consistently?
A standing cross-functional steering committee with senior management/board reporting provides a formal, recurring mechanism for legal, risk, IT, and business stakeholders to align security strategy with enterprise objectives — this is the governance structure ISACA identifies for sustained strategic alignment.
Question 4 of 6 · Domain 1: Information Security Governance
A business unit requests an exception to a security policy that would result in residual risk exceeding the risk appetite formally approved by the board. Per sound governance practice, which approval path is MOST appropriate for this exception?
When an exception pushes residual risk above the board-approved appetite, governance requires escalation to the level accountable for that appetite — typically senior management or an executive risk committee — with explicit sign-off and compensating controls, not unilateral approval at a lower level.
Question 5 of 6 · Domain 1: Information Security Governance
Which statement BEST captures the distinction between information security governance and information security management as defined in the CISM framework?
CISM explicitly distinguishes governance (direction-setting, oversight, accountability performed by the board/senior management) from management (execution and operation of the program, performed by the CISO and security team) — this hierarchy is foundational to Domain 1.
Question 6 of 6 · Domain 1: Information Security Governance
A company operating across the EU and a country with strict data-localization law is pursuing an enterprise-wide public cloud migration strategy already funded by the board. The CISO learns the localization law may conflict with the planned architecture. What is the BEST next step before the migration proceeds?
Governance requires that legal, regulatory, and contractual requirements be identified and assessed for business impact before an architecture decision proceeds, so the board can make an informed decision balancing the business case against compliance obligations — this is a core governance responsibility of the CISM role, not a purely legal or technical matter.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.