- Home
- All questions
- Security governance
CISM study material: Security governance
185 questions of the 1000 in the CISM — Certified Information Security Manager quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 1. A security manager is presenting the organisation's adoption of NIST CSF 2.0 to the board. A director asks why Govern is drawn at the centre of the framework wheel rather than as the first step in a sequence. What is the most accurate explanation?
- 2. An organisation is migrating from CSF 1.1 to CSF 2.0 and the manager must brief staff on what structurally changed at the highest level of the framework. Which statement is correct?
- 3. During a governance review, the manager finds that executives have a shared but unwritten sense of how much risk is acceptable, and business units interpret it differently. Which CSF 2.0 Govern outcome is not being met?
- 4. Three business units each rate their top risk as high, but each derives that rating differently, so the executive committee cannot tell which risk deserves funding first. Which governance outcome most directly addresses this?
- 5. A manager is drafting the agenda for the quarterly cybersecurity risk discussion under CSF 2.0. Which item belongs on that agenda that a purely threat-focused agenda would omit?
- 6. After a serious incident, the board asks who is ultimately accountable for cybersecurity risk. The security manager wants to answer consistently with CSF 2.0. Which answer is correct?
- 7. A security strategy names supply chain risk as its highest priority, yet the budget allocates almost nothing to supplier assurance while funding a large endpoint refresh. Which CSF 2.0 Govern outcome is not being satisfied?
- 8. An auditor notes the organisation's information security policy was approved six years ago and has not been touched since, although the organisation has since adopted cloud hosting and entered a regulated market. What is the governance failing?
- 9. The organisation produces detailed quarterly risk performance reports, but the security strategy has never been amended in response to them. Which CSF 2.0 Govern category is not functioning?
- 10. A manager is preparing to use CSF Organizational Profiles for the first time and must explain the difference between the two profile types to the steering group. Which pairing is correct?
- 11. An organisation has completed both its Current and Target CSF Profiles. What is the next step in the CSF sequence, and what does it produce?
- 12. A mid-sized organisation in a regulated sector has limited capacity to design a Target Profile from scratch. Which CSF resource is intended to serve as its starting point?
- 13. A consultant tells the board the organisation should aim for CSF Tier 4 because higher tiers are always better. How should the security manager correct this?
- 14. An assessment finds that management has approved the organisation's risk management practices, but they are not established as organisation-wide policy. Which CSF Tier does this best describe?
- 15. At which CSF Tier would you expect executives to weigh cybersecurity risk alongside financial risk, with the organisational budget itself shaped by the predicted risk environment and risk tolerance?
- 16. In the CSF risk communication model, which description correctly matches each layer to what it contributes?
- 17. A privacy officer argues that if the organisation prevents all security incidents, it will have no privacy risk. How should the security manager respond, consistent with CSF 2.0?
- 18. A multinational asks why the CSF can be applied across its operations in several countries and industries without being rewritten for each. What property of the framework explains this?
- 19. A newly appointed security manager wants to structure risk management across the organisation using SP 800-39. Which description of the three tiers is correct?
- 20. An organisation is starting to apply SP 800-39 and asks which risk management component belongs at Tier 1 and why it must come first. What is the correct answer?
- 21. A design review proposes to complete the enterprise architecture and then add a separate information security architecture layer beside it. Why does SP 800-39 regard this as wrong?
- 22. A vulnerability discovered in one system turns out to stem from a design pattern reused across the estate. According to SP 800-39, what should follow?
- 23. The board asks the security manager for a definition of governance it can apply beyond security. Which of these matches the definition SP 800-39 uses?
- 24. A security manager is asked which outcomes a governance programme should deliver for risk management under SP 800-39. Which two are among the five named outcomes? Choose two.
- 25. In a large organisation, legal, finance, IT and security each run their own governance forum, and their decisions increasingly conflict. What does SP 800-39 advise?
- 26. An organisation is choosing between centralised, decentralised and hybrid governance models for security. Whichever model is selected, what does SP 800-39 insist upon?
- 27. A manager reads that the organisation must establish a risk executive and assumes this means recruiting an individual into a new post. How should this be corrected under SP 800-39?
- 28. Each system owner reports that risk to their own system is acceptable, yet the organisation wants to know whether risk is acceptable overall. Which role produces that view under SP 800-39?
- 29. A parent organisation must decide how much freedom its subsidiaries have to run their own risk processes. Under SP 800-39, which function specifies that degree of autonomy?
- 30. A security manager is drafting the organisation-wide risk management strategy. Which two elements does SP 800-39 expect it to contain? Choose two.
- 31. An organisation publishes a one-line risk tolerance statement on its intranet, yet staff continue to make inconsistent decisions. What does SP 800-39 say was missing?
- 32. Following a major loss, an executive argues they cannot be held responsible because they personally approved no individual risk decision. Under SP 800-39, why is this defence incomplete?
- 33. An enterprise risk officer worries that adopting SP 800-39 will duplicate the existing enterprise risk management programme. How should the security manager characterise the relationship?
- 34. An organisation must satisfy both ISO/IEC management system requirements and NIST guidance, and its manager fears running two incompatible processes. What did NIST do to reduce that burden?
- 35. A candidate is asked to define information security governance in management terms rather than technical ones. Which definition matches NIST's?
- 36. A manager is building out the organisation's security governance and wants to cover the components NIST identifies. Which two are among those components? Choose two.
- 37. A reviewer cannot tell why the security strategy contains a particular goal, because nothing links it to anything the business has stated it wants. What quality is the strategy lacking?
- 38. The security strategy is reviewed annually by calendar. Which two circumstances does NIST say should also trigger a revisit before the next annual review? Choose two.
- 39. In one organisation the security head controls the line-item budget for all security activity and every security practitioner reports into that office. Which governance structure does this describe?
- 40. A group security office writes policy and provides oversight, but each operating unit funds its own security programme and its security officers report to their unit heads. Which structure is this?
- 41. A manager benchmarks peers and finds none operate a purely centralised or purely decentralised security governance structure. What does NIST say about this observation?
- 42. An organisation is deciding how centralised its security governance should be. Which two factors does NIST name as bearing on that decision? Choose two.
- 43. Having chosen a hybrid governance structure, an organisation's leadership treats the decision as settled permanently. What does NIST say about that assumption?
- 44. A business unit head is told they are responsible for securing their operations, but they cannot approve spending, hire staff or mandate controls in their own unit. Which governance principle is breached?
- 45. An organisation appoints its network operations lead to also act as senior information security officer, alongside their existing duties. Which expectation in the NIST role definition is not met?
- 46. An assessment repeatedly finds the same deficiencies year after year, with no record of what was done about earlier findings. Which senior security officer responsibility is not being discharged?
- 47. A new senior information security officer reviews their remit. Which two duties does NIST place with that role? Choose two.
- 48. A board member asks which internal function independently assesses security practice, detects waste and misuse, and recommends how to prevent recurrence. Which role is described?
- 49. A proposed monitoring capability would improve threat detection but capture far more employee personal data than the current tooling. Which role is specifically charged with holding the balance in this decision?
- 50. Two employees commit the same policy violation, and one is dismissed while the other receives no sanction. Which role owns the practice that failed here?
- 51. A data centre review must cover controls that fall outside the information security officer's direct remit. Which two areas does NIST place with the physical security officer? Choose two.
- 52. A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?
- 53. An enterprise architect delivers a completed target architecture and then asks the security team to identify where controls should be added. Why is this sequence wrong under NIST guidance?
- 54. A manager must explain to a new starter what the organisation's information security policy actually is, in NIST's terms. Which description is correct?
- 55. An organisation has a governance committee, defined roles and an approved strategy, but no written security policy. Why does NIST regard this as a fundamental weakness?
- 56. A drafter builds the organisation's security policy purely from an external control framework, with no other input. Which two further inputs does NIST expect the policy to be built from? Choose two.
- 57. A security policy is reviewed and found to name roles and set a control baseline, but staff say they do not know what conduct is expected of them or what happens if they fall short. Which required element is missing?
- 58. A team issues a procedure that relaxes a requirement stated in the approved security policy, arguing the procedure is more current. How should the security manager respond?
- 59. Physical security policy grants building access on one basis while information security policy grants system access on another, and the two contradict for contractors. What does NIST advise?
- 60. A manager sets up ongoing monitoring of the security programme itself. Which two questions does NIST say that monitoring should answer? Choose two.
- 61. Policies that were entirely adequate at approval are found three years later to be inadequate although nothing was formally changed. Which cause does NIST specifically name alongside changed mission and technology?
- 62. A manager is challenged that periodic assessments are pure overhead because most come back clean. Which two additional purposes does NIST attribute to them? Choose two.
- 63. An organisation subject to several regulators finds their requirements pull in different directions on evidence and reporting. How does NIST characterise this situation?
- 64. A security manager notices that individuals with assigned security responsibilities face no consequence when they simply fail to act. Which of NIST's keys to good governance is being neglected?
- 65. Security planning happens in the security office and is presented to the business only once complete, separately from strategic and capital planning. Which NIST governance practice does this violate?
- 66. Monitoring consistently shows that one control family underperforms, but funding allocations the following year are unchanged. Which governance practice is not working?
- 67. Under IR 8286, which governance responsibility sits with executive leaders in relation to risk?
- 68. An organisation set its risk strategy three years ago and treats it as settled. According to IR 8286, why is this inadequate?
- 69. IR 8286 distinguishes two risk officer roles. Which pairing correctly describes them?
- 70. An enterprise risk steering committee wants assurance that the risk process it mandated is genuinely being applied across the business. Which role provides that?
- 71. Stakeholders in a risk process repeatedly disagree over who decides and who merely comments. Which tool does IR 8286 suggest to settle this?
- 72. An organisation assigns a large portfolio of risks to an owner who has no training or experience in that domain. What does IR 8286 say about this arrangement?
- 73. An enterprise risk committee receives risk input, but human resources, legal, audit and compliance are unaware of its work and of the subordinate councils feeding it. What does IR 8286 recommend?
- 74. A system owner proposes to decide their system's risk treatment purely on the system's own technical merits. Which two organisational factors does SP 800-37 say such decisions are also tied to? Choose two.
- 75. An organisation skips the RMF Prepare step at the organisational level and starts categorising systems immediately. Which consequences does NIST predict?
- 76. A consolidation programme reduces the number of distinct platforms in the estate. Beyond cost, what security benefit does SP 800-37 attribute to consolidation, optimisation and standardisation?
- 77. Two divisions of the same group manage risk very differently, one by top-down direction and the other by consensus among peers. What does SP 800-37 require despite this difference?
- 78. Risk management tasks are assigned but consistently go undone, and investigation shows staff were named without being funded or freed from other duties. Which requirement was not met?
- 79. A governance model pushes risk direction downward from the organisation to systems, but nothing flows back up. What does the NIST multi-level model require?
- 80. A manager must explain what an authorisation boundary determines. Which answer is correct?
- 81. A manager must define trust for a governance paper on external partnerships, using SP 800-39's meaning. Which definition is correct?
- 82. A partner is trusted to handle routine scheduling data but the same partner is not trusted with regulated health records. Which property of trust does this illustrate?
- 83. A supplier the organisation trusts subcontracts part of the work to a firm the organisation has never assessed, and argues that its own trusted status should carry over. Which property of trust rebuts this?
- 84. A due diligence report claims a supplier's trustworthiness cannot be evaluated because trust is subjective. How should the security manager respond under SP 800-39?
- 85. A business unit wants to establish a data-sharing partnership and treats the trust decision as a commercial matter outside the risk process. How does SP 800-39 characterise such a decision?
- 86. An organisation is preparing to rely on an external service provider. Which two things does SP 800-39 say it must establish? Choose two.
- 87. A risk assessment of partners considers only competitors and known adversaries as sources of concern. Which category does SP 800-39 warn is being missed?
- 88. Two organisations in a partnership want to build trust through transparency about risk. Which two mechanisms does SP 800-39 describe for achieving that? Choose two.
- 89. A security architecture allocates controls so that a failure of any one layer is covered by another, and so that similar protections come from diverse sources. Which two concepts does SP 800-39 name for this? Choose two.
- 90. Two years after an architectural decision, nobody can explain why a particular risk trade-off was made. Which SP 800-39 practice would have prevented this?
- 91. A project plans to gather functional requirements first and add security requirements once the design is stable. Why does SP 800-39 object?
- 92. A requirements document lists the security functions a system must provide but says nothing about how much assurance is needed in them. What has been omitted under SP 800-39?
- 93. A system cannot achieve the level of trustworthiness needed from its technical controls alone. What does SP 800-39 say the organisation should do?
- 94. A board paper argues resilience is a technical property of no interest to executives. How does SP 800-39 frame resilience?
- 95. A technology the business insists on adopting carries vulnerabilities that no available control adequately addresses. Which response does SP 800-39 identify for this situation?
- 96. A manager is aligning security activities to the system development life cycle. Which sequence of phases does NIST describe?
- 97. A programme treats its life cycle as strictly one-directional, refusing to revisit earlier phases. What does NIST say about this?
- 98. Servers are being retired and sent for disposal. Which two actions does SP 800-39 expect at this life cycle phase? Choose two.
- 99. A system is about to go live and the project manager proposes assessing control effectiveness after six months of operation. Why does SP 800-39 place that assessment earlier?
- 100. A security manager is told to justify why security investments must be ranked rather than all funded. Which reasoning matches NIST's capital planning guidance?
- 101. An investment management model has three phases. Which set correctly names them and their focus?
- 102. In the Select phase of investment management, on which three criteria are projects analysed and ranked before a portfolio is chosen?
- 103. A programme discovers cost overruns only at delivery. Which investment phase and mechanism was intended to catch them earlier?
- 104. Security drivers differ across the investment life cycle. Which two pairings are correct? Choose two.
- 105. An organisation begins the seven-step process for integrating security into capital planning. What is the first step?
- 106. Which two criteria does NIST use to prioritise potential enterprise-level security investments in the capital planning process? Choose two.
- 107. When assembling a security investment portfolio, several priorities compete: an internal modernisation goal, a departmental preference, and a statutory obligation. Which does NIST say ranks highest?
- 108. A security manager wants weaknesses found during assessment to actually attract funding. Which mechanism does NIST describe for connecting the two?
- 109. A manager defines the purpose of the organisation's risk monitoring. Which two purposes does SP 800-39 name? Choose two.
- 110. At the organisation tier, what kind of monitoring activity does SP 800-39 describe as appropriate?
- 111. An organisation sets every monitoring activity to an annual cadence regardless of subject. Which three inputs does SP 800-39 say should shape monitoring frequency instead?
- 112. A risk assessment established a likelihood threshold for a particular threat. How can monitoring use that threshold, according to SP 800-39?
- 113. Before choosing among risk responses, a manager lists the constraints already fixed by framing. Which two does SP 800-39 name? Choose two.
- 114. A risk register records only risks the organisation faces today. Which category does SP 800-39 say is also in scope?
- 115. A manager must explain what risk framing produces. What is its principal output under SP 800-39?
- 116. At the organisation tier, senior leaders define the risk frame. Which two aspects of monitoring do they settle there? Choose two.
- 117. An organisation has never articulated its assumptions, constraints, tolerance or trade-offs for risk. What consequence does SP 800-39 predict?
- 118. Two divisions of the same organisation hold materially different risk tolerances, grounded in their different operating realities. What does SP 800-39 say leadership should do?
- 119. Which two organisational realities does SP 800-39 say shape how an organisation frames risk? Choose two.
- 120. An organisation wants to begin risk framing. What does SP 800-39 identify as the key precondition?
- 121. While developing response options, a team finds a promising approach that the organisation's stated constraints had ruled out entirely. What does SP 800-39 say should happen?
- 122. Monitoring shows the organisation is routinely carrying far more risk than its published tolerance statement allows, with no adverse consequence to date. What does SP 800-39 say this may indicate?
- 123. An organisation with a hybrid governance structure asks how many risk assessment methodologies it should use. What does SP 800-39 suggest is appropriate?
- 124. An organisation whose culture prizes divisional autonomy does not want to mandate one risk methodology. Which approach does SP 800-39 offer?
- 125. A threat assumptions document lists the threat sources the organisation's controls are designed to address. What does SP 800-39 say it should also record?
- 126. An organisation wants to be able to roll up risk assessment results from many business areas into an organisation-wide view. What does SP 800-39 say makes this possible?
- 127. A programme manager complains that early-phase threat analysis is less specific than the analysis done nearer deployment. How does SP 800-39 characterise this?
- 128. An assessment scopes vulnerabilities to weaknesses in assets the organisation owns and controls. Which class of vulnerability does SP 800-39 say is being missed?
- 129. SP 800-39 describes impact being felt at three levels. Which set matches?
- 130. Personal data exposed by the human resources function damages the whole organisation's reputation, while also making it easier for an attacker to defeat authentication on many systems. Which point does SP 800-39 illustrate with such an example?
- 131. An organisation wants to reuse one division's risk assessment results in another division. Which two factors determine how far that reuse is legitimate? Choose two.
- 132. A decentralised organisation performs most risk assessment at the business process tier. What does SP 800-39 say this creates a greater need for?
- 133. A manager must justify the effort of keeping risk assessments current rather than repeating them from scratch each year. Which two benefits does SP 800-39 name? Choose two.
- 134. SP 800-39 distinguishes two lighter forms of reassessment. Which pairing is correct?
- 135. A team must assess risk before the organisation has finished defining its risk frame. What does SP 800-39 permit and warn?
- 136. Which two kinds of vulnerability does SP 800-39 say are identified most effectively at the organisation tier rather than lower down? Choose two.
- 137. An organisation prioritises remediating system-level flaws over addressing a weakness in its business process design. What does SP 800-39 warn about that ordering?
- 138. Two comparable organisations run the same assessment process, but one consistently surfaces far more threat and vulnerability information from its own staff. Which factor does SP 800-39 identify as the likely cause?
- 139. An assessment examines only those threats for which the organisation already has safeguards deployed. What does SP 800-39 say is missing?
- 140. Two experienced assessors reach different risk conclusions from the same evidence. How does SP 800-39 treat this outcome?
- 141. A manager considers using a panel of assessors with varied backgrounds. Which two effects does SP 800-39 attribute to that diversity? Choose two.
- 142. A candidate asks how the CISM examination is structured. Which description is correct?
- 143. Which two statements about the weighting of CISM domains are correct? Choose two.
- 144. CISM Domain 1 is divided into two parts. Which pairing is correct?
- 145. Under CISM's enterprise governance subtopic, which two subjects are examined? Choose two.
- 146. CISM examines strategic planning within the information security strategy subtopic. Which three concerns does it specifically name?
- 147. A manager is about to draft a new information security strategy. Which CISM task should come before the strategy itself is written?
- 148. An organisation runs its security governance as a separate structure with its own committees, reporting lines and calendar, parallel to corporate governance. Which CISM task is not being fulfilled?
- 149. In the CISM document hierarchy, what is the stated relationship between policies and standards, procedures and guidelines?
- 150. A security manager argues that justifying funding is the finance function's job, not theirs. How does the CISM job practice treat this?
- 151. An organisation secured executive sign-off for its security strategy at launch and has not revisited that support since. Which CISM task is incompletely performed?
- 152. Which two reporting duties does the CISM job practice assign to the security manager? Choose two.
- 153. A manager assumes that meeting the organisation's own internal policy is sufficient to satisfy CISM's compliance expectations. What does the job practice require in addition?
- 154. An implementation team treats every CSF subcategory as a mandatory action item to be ticked off. Why is this a misreading of the framework?
- 155. Which two of the following are categories within the CSF 2.0 Govern function? Choose two.
- 156. An organisation files its legal, regulatory and contractual cybersecurity obligations under its compliance programme and nowhere else. Where does CSF 2.0 locate that outcome?
- 157. Under CSF 2.0, screening at hiring, onboarding and departure processes for staff are addressed under which Govern category?
- 158. An organisation wants separate CSF Profiles for its payments platform and for its ransomware readiness. Is this consistent with the framework?
- 159. CSF 2.0 supplies two kinds of supplementary online resource. Which pairing describes them correctly?
- 160. Which two activities does SP 800-39 place at Tier 2, the mission and business process level? Choose two.
- 161. Senior leaders working with the risk executive function must settle three things about risk decisions. Which of these is one of them?
- 162. A manager is asked to state the purpose of information security governance in one sentence for the annual report. Which formulation matches NIST's?
- 163. A security programme definition names its mission, vision, goals and objectives, and sets out a high-level plan with short and mid-term targets. Which element does NIST say is still missing?
- 164. A security manager wants to reorganise security governance in a way the wider organisational structure does not support. What does NIST observe about such situations?
- 165. Which two responsibilities does NIST assign to the chief information officer in the security governance model? Choose two.
- 166. Which two duties does NIST place with the senior information security officer? Choose two.
- 167. Which role reviews the cost goals of each major security investment and passes investment assessments to the investment review board?
- 168. An organisation declines to share any information with a partner because it cannot establish complete trust. How does SP 800-39 characterise this position?
- 169. What benefit does SP 800-39 attribute to embedding the organisation's risk management strategy within its enterprise architecture?
- 170. During design, an assessment shows a proposed component carries known weaknesses that a comparable alternative does not. What does SP 800-39 identify as the advantage of switching at this point?
- 187. Which two of the following does SP 800-30 recognise as vulnerabilities in governance structures themselves? Choose two.
- 230. A vulnerability register covers only information systems. Which two further locations does SP 800-39 say organisational vulnerabilities can occupy? Choose two.
- 271. Two comparable organisations receive the same system-level risk data, but one translates it into enterprise understanding far more readily. Which structural difference does IR 8286 identify?
- 310. Stakeholders in different units assign different priorities to risks with identical exposure values. Which governance step does IR 8286 say prevents this?
- 463. An organisation's monitoring strategy is drafted at the business process tier. What does SP 800-137 require before it takes effect?
- 465. Which two constraints does SP 800-137 say may limit the decisions of officials at the upper tiers? Choose two.
- 689. How does NIST say measurement strengthens governance?
- 738. What does the Community Profile recommend be taken into account when the organisation adjusts its cybersecurity risk management strategy?
- 868. Which two things does a contingency planning policy statement establish, and what does NIST say it needs to succeed?
- 910. Which review does NIST require before an alternate site agreement is relied on?
- 918. Which role does NIST say a recovery strategy must include, and what decision rests with it?
- 945. Why does NIST require the distribution of a contingency plan to be marked and controlled, with a record of holders?
- 951. How many people does NIST say should hold the authority to activate the contingency plan?
- 975. How does NIST separate the plan coordinator's role from the exercise programme coordinator's?
- 984. Which approval does NIST treat as an essential development step for an exercise?