exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 973 discussion

Actual exam question from Isaca's CISM
Question #: 973
Topic #: 1
[All CISM Questions]

Which of the following BEST indicates that information security governance and corporate governance are integrated?

  • A. The information security team is aware of business goals.
  • B. A cost-benefit analysis is conducted on all information security initiatives.
  • C. The board is regularly informed of information security key performance indicators (KPIs).
  • D. The information security steering committee is composed of business leaders.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
afc1019
Highly Voted 1 year, 3 months ago
Selected Answer: D
D. The information security steering committee is composed of business leaders. This is because the information security steering committee is responsible for overseeing the organization's information security program and by having business leaders on the steering committee, it ensures that information security is aligned with the organization's business goals.
upvoted 7 times
...
hargit
Most Recent 3 months, 1 week ago
Selected Answer: C
The BEST indicator that information security governance and corporate governance are integrated is when the board is regularly informed of information security key performance indicators (KPIs) (Option C). This demonstrates that information security is being monitored and managed at the highest level of the organization, ensuring alignment with overall business objectives and strategic priorities (CoPilot)
upvoted 1 times
...
POWNED
10 months, 2 weeks ago
Selected Answer: D
Most CISM questions have a key word, this question is integrate. When it comes to The board and KPIs the key word in that answer for me would be support. When it comes to steering committee I think of integration.
upvoted 1 times
Marcelus1714
10 months ago
agree with you, when I saw "integrate" I saw D
upvoted 1 times
Marcelus1714
10 months ago
If you check C how is it related to "integration" between both things?... Is it about to INFORM the board, not to integrate anything...
upvoted 1 times
...
...
...
TamerBeSafe
10 months, 3 weeks ago
Selected Answer: C
C. The board is regularly informed of information security key performance indicators (KPIs). When the board is regularly informed about information security key performance indicators, it demonstrates a strong integration of information security governance with corporate governance. This means that information security is considered a critical aspect of overall business strategy and decision-making. Regular reporting to the board helps align information security efforts with business objectives and ensures that security is viewed as an integral part of the organization's governance structure. While the other options (A, B, and D) are important considerations for effective information security governance, regular reporting to the board about key performance indicators directly involves top-level decision-makers and signifies a high level of integration between information security and corporate governance.
upvoted 2 times
...
Uncle_Lucifer
1 year ago
Selected Answer: C
D is wrong. Even is business owners are in security committee, it should also include other cross functional teams. Answer is C
upvoted 3 times
...
Uncle_Lucifer
1 year ago
D is wrong. Even is business owners are in security committee, it should also include other cross functional teams. Answer is C
upvoted 1 times
...
Soleandheel
1 year ago
D. The information security steering committee is composed of business leaders. C. is wrong because the Board of Directors of an organization don't usually focus on Metrics like KPIs. These are the focus of Management. The Board usually focused on very High-level business objectives. So regularly updating them with KPI's would be some how inappropriate. As such, answer option D makes the most sense.
upvoted 4 times
Soleandheel
1 year ago
Maybe inappropriate is not the right word....let's say out-of-place.
upvoted 2 times
...
...
Cyberbug2021
1 year ago
Selected Answer: C
This option indicates that information security governance and corporate governance are integrated because it demonstrates that the board is taking an active role in overseeing the organization's information security program. By regularly reviewing information security KPIs, the board can ensure that the program is aligned with the organization's overall goals and objectives and that it is effectively managing risk. having members on the steering committee does not gurantee integration - but KPIs would
upvoted 2 times
...
richck102
1 year, 1 month ago
D. The information security steering committee is composed of business leaders.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: D
This shows that information security decisions and strategies are being made in collaboration with key stakeholders from the business side, which aligns information security efforts with the broader corporate governance framework.
upvoted 3 times
...
Saisharan
1 year, 2 months ago
So what is the correct answer
upvoted 1 times
...
CISSPST
1 year, 2 months ago
Selected Answer: C
Look at it this way. Should the company have a Corporate governance committee, it would be reporting/aligning to the board, not the security steerco. Board is accountable for governance, not security steerco.
upvoted 3 times
...
iacini
1 year, 3 months ago
Selected Answer: D
I would go with D as in my opinion this refers to the integration the most.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...