nerdexam
Isaca

CISM · Question #10

The effectiveness of an information security governance framework will BEST be enhanced if:

The correct answer is D. risk management is built into operational and strategic activities. The effectiveness of an information security governance framework is best enhanced when risk management is thoroughly integrated into both operational and strategic activities.

Submitted by skyler.x· Apr 18, 2026Information Security Governance

Question

The effectiveness of an information security governance framework will BEST be enhanced if:

Options

  • Aconsultants review the information security governance framework
  • BIS auditors are empowered to evaluate governance activities
  • Ca culture of legal and regulatory compliance is promoted by management
  • Drisk management is built into operational and strategic activities

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    11% (2)
  • D
    79% (15)

Why each option

The effectiveness of an information security governance framework is best enhanced when risk management is thoroughly integrated into both operational and strategic activities.

Aconsultants review the information security governance framework

Consultants reviewing the framework can provide valuable insights but is a one-time or periodic activity, not a continuous enhancement like integrating risk management.

BIS auditors are empowered to evaluate governance activities

Empowering IS auditors to evaluate governance activities is important for oversight and assurance, but it is a control mechanism, not the primary driver for enhancing the framework's inherent effectiveness.

Ca culture of legal and regulatory compliance is promoted by management

Promoting a culture of compliance is beneficial for adherence to rules, but it's a component of a strong governance framework rather than the overarching enhancement that integrates risk into core business functions.

Drisk management is built into operational and strategic activitiesCorrect

Integrating risk management into both operational and strategic activities ensures that security considerations are embedded throughout the organization's decision-making processes, from daily tasks to long-term planning. This proactive approach allows governance to guide and influence security outcomes at every level, making the framework truly effective and pervasive.

Concept tested: Information security governance effectiveness

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Information Security Governance#Risk Management Integration#Strategic Alignment#Framework Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice