nerdexam
Isaca

CISM · Question #6

Which of the following is the PRIMARY responsibility of an information security governance committee?

The correct answer is B. Approving changes to the information security strategy. The primary responsibility of an information security governance committee is to approve changes to the information security strategy, ensuring alignment with overall business objectives and risk appetite.

Submitted by daniela_cl· Apr 18, 2026Information Security Governance

Question

Which of the following is the PRIMARY responsibility of an information security governance committee?

Options

  • AReviewing the information security risk register
  • BApproving changes to the information security strategy
  • CDiscussing upcoming information security projects
  • DReviewing monthly information security metrics

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    87% (20)
  • C
    4% (1)

Why each option

The primary responsibility of an information security governance committee is to approve changes to the information security strategy, ensuring alignment with overall business objectives and risk appetite.

AReviewing the information security risk register

Reviewing the risk register is an important task, but it's often delegated or a more operational/tactical review rather than the committee's primary, overarching strategic responsibility.

BApproving changes to the information security strategyCorrect

A governance committee operates at a strategic level, setting the direction and ensuring that the information security strategy aligns with the organization's mission, vision, and risk tolerance. Approving strategic changes ensures that security efforts are always in lockstep with business priorities and regulatory requirements.

CDiscussing upcoming information security projects

Discussing upcoming projects falls more into the realm of project management or operational planning, not the highest-level strategic governance of the entire program.

DReviewing monthly information security metrics

Reviewing monthly metrics is an oversight activity to gauge program performance, but the primary role of governance is to establish and adjust the strategy that those metrics measure.

Concept tested: Information security governance committee responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Information Security Governance#Governance Committee#Security Strategy#Strategic Oversight

Community Discussion

No community discussion yet for this question.

Full CISM Practice