nerdexam
Isaca

CISM · Question #16

Which of the following is the MOST important function of an information security steering committee?

The correct answer is D. Obtaining multiple perspectives from the business. The most critical function of an information security steering committee is to gather diverse business perspectives to align security initiatives with organizational goals and risks.

Submitted by tom_us· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST important function of an information security steering committee?

Options

  • AAssigning data classifications to organizational assets
  • BDefining security standards for logical access controls
  • CDeveloping organizational risk assessment processes
  • DObtaining multiple perspectives from the business

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    9% (3)
  • D
    74% (26)

Why each option

The most critical function of an information security steering committee is to gather diverse business perspectives to align security initiatives with organizational goals and risks.

AAssigning data classifications to organizational assets

Assigning data classifications is an operational task often performed by data owners or information security teams based on policies set by governance, not the primary function of a high-level steering committee.

BDefining security standards for logical access controls

Defining security standards for logical access controls is a detailed policy-level activity, often delegated by the steering committee to technical or policy teams.

CDeveloping organizational risk assessment processes

Developing organizational risk assessment processes is a function typically performed by the risk management team, with oversight from the steering committee, rather than being the committee's *primary* function.

DObtaining multiple perspectives from the businessCorrect

An information security steering committee, composed of representatives from various business units, ensures that security strategies and investments are aligned with overall business objectives and address diverse departmental needs and risks. This cross-functional perspective is crucial for gaining buy-in, ensuring relevance, and integrating security effectively across the organization.

Concept tested: Information security governance role

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Information Security Governance#Steering Committee#Stakeholder Management#Business Alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice