nerdexam
Isaca

CISM · Question #530

Which of the following is the MOST important consideration when establishing an information security governance framework?

The correct answer is C. Defining roles and responsibilities. Defining roles and responsibilities (C) is the foundational element of any governance framework because governance is fundamentally about accountability - who owns what decisions, who is responsible for outcomes, and who has authority to act. Without clear role definitions…

Submitted by ravi_2018· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST important consideration when establishing an information security governance framework?

Options

  • AIntegrating physical security and information security
  • BDeveloping calculation methods for return on investment (ROI)
  • CDefining roles and responsibilities
  • DAugmenting security staff

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    11% (4)
  • C
    68% (26)
  • D
    5% (2)

Explanation

Defining roles and responsibilities (C) is the foundational element of any governance framework because governance is fundamentally about accountability - who owns what decisions, who is responsible for outcomes, and who has authority to act. Without clear role definitions, policies lack owners, controls lack enforcers, and the entire framework collapses into ambiguity.

Why the distractors fall short:

  • (A) Integrating physical and information security is a valid best practice but is an outcome of good governance design, not a prerequisite for establishing the framework itself.
  • (B) ROI calculations are useful for justifying security investments to leadership, but financial metrics are a management tool, not a governance foundation.
  • (D) Augmenting security staff is an operational/resource decision - governance defines the structure, not the headcount.

Memory tip: Think of governance as an org chart before it's a budget. You can't govern anything if nobody knows who's in charge. The acronym RACI (Responsible, Accountable, Consulted, Informed) is a governance staple - and it's all about roles, making C the natural anchor of any framework.

Topics

#Information Security Governance#Roles and Responsibilities#Governance Framework#Accountability

Community Discussion

No community discussion yet for this question.

Full CISM Practice