nerdexam
Isaca

CISM · Question #637

Which of the following would BEST enable a new information security manager to assess the current state of information security governance within the organization?

The correct answer is D. Analyzing the integration of information security policies and practices within business processes. Analyzing how security policies and practices are integrated into business processes directly reveals whether governance is functioning in practice - not just on paper - making it the most comprehensive lens for assessing the current state of governance. A BIA (A) focuses on…

Submitted by javi_es· Apr 18, 2026Information Security Governance

Question

Which of the following would BEST enable a new information security manager to assess the current state of information security governance within the organization?

Options

  • AConducting a business impact analysis (BIA) to understand business priorities
  • BInterviewing key personnel identified within the governance framework
  • CPerforming both quantitative and qualitative risk analyses
  • DAnalyzing the integration of information security policies and practices within business processes

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    32% (7)
  • D
    50% (11)

Explanation

Analyzing how security policies and practices are integrated into business processes directly reveals whether governance is functioning in practice - not just on paper - making it the most comprehensive lens for assessing the current state of governance. A BIA (A) focuses on business continuity priorities, not governance maturity, so it answers the wrong question. Interviewing personnel (B) is useful but narrow - it captures individual perspectives rather than systemic integration across the organization. Risk analysis (C) measures risk exposure, which is an input to governance, not an assessment of governance itself.

Memory tip: Think "governance = integration." Good governance isn't a document or a conversation - it's security woven into how the business actually operates. If you can see it in the processes, governance is real; if it only lives in policy binders, it isn't.

Topics

#Information Security Governance Assessment#Governance Effectiveness#Security Integration#Organizational Embedding

Community Discussion

No community discussion yet for this question.

Full CISM Practice