nerdexam
Isaca

CISM · Question #316

Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?

The correct answer is D. Consistent execution of information security strategy. Why D is correct: A governance framework's primary purpose is to provide structure, accountability, and direction - ensuring that security strategy is executed consistently across the entire organization, regardless of department or personnel. Governance aligns actions with…

Submitted by rania.sa· Apr 18, 2026Information Security Governance

Question

Which of the following should be the PRIMARY expectation of management when an organization introduces an information security governance framework?

Options

  • AOptimized information security resources
  • BIncreased influence of security management
  • CImproved organization-wide security awareness training
  • DConsistent execution of information security strategy

How the community answered

(25 responses)
  • C
    4% (1)
  • D
    96% (24)

Explanation

Why D is correct: A governance framework's primary purpose is to provide structure, accountability, and direction - ensuring that security strategy is executed consistently across the entire organization, regardless of department or personnel. Governance aligns actions with policy; without consistent execution, the framework has no practical value.

Why the distractors are wrong:

  • A (Optimized resources): Resource optimization may be a benefit of governance, but it's a secondary outcome, not the primary expectation. Governance is about direction and accountability, not efficiency alone.
  • B (Increased influence of security management): Governance is about organizational alignment, not expanding any team's political power. Influence may shift, but that's a side effect, not a goal.
  • C (Improved security awareness training): Training is a control - one specific tool within a security program. A governance framework encompasses far more than training and isn't introduced primarily to improve it.

Memory tip: Think of governance as the "steering wheel" of security - its job is to keep the whole organization moving in the same direction (consistent execution of strategy). Resources, influence, and training are parts of the engine, not the steering mechanism.

Topics

#Information Security Governance Framework#Strategy Execution#Management Expectations#Organizational Objectives

Community Discussion

No community discussion yet for this question.

Full CISM Practice