nerdexam
Isaca

CISM · Question #719

Which of the following should be established FIRST when implementing an information security governance framework?

The correct answer is A. Security policies. Security policies must be established first because they define the organization's security objectives, principles, and requirements - essentially the "rules of the game" that everything else is built upon. Without documented policies, there is no authoritative foundation to guid

Submitted by marco_it· Apr 18, 2026Information Security Governance

Question

Which of the following should be established FIRST when implementing an information security governance framework?

Options

  • ASecurity policies
  • BSecurity incident management team
  • CSecurity architecture
  • DSecurity awareness training program

How the community answered

(63 responses)
  • A
    87% (55)
  • B
    5% (3)
  • C
    2% (1)
  • D
    6% (4)

Explanation

Security policies must be established first because they define the organization's security objectives, principles, and requirements - essentially the "rules of the game" that everything else is built upon. Without documented policies, there is no authoritative foundation to guide what architecture to design, who to train, or what incidents to respond to.

  • B (Incident management team) is wrong because the team needs policies to know what constitutes an incident and how to respond - you can't operationalize a function without its governing rules.
  • C (Security architecture) is wrong because architecture decisions must align with policy requirements; building architecture first risks designing a system that contradicts later-defined organizational intent.
  • D (Security awareness training) is wrong because training must teach employees what the policies require - if no policies exist, there is nothing substantive to train on.

Memory tip: Think of governance as building a house - policies are the blueprint. You don't hire a crew (incident team), frame walls (architecture), or train workers (awareness) before the blueprint exists.

Topics

#Information security governance#Security policies#Framework implementation#Foundational elements

Community Discussion

No community discussion yet for this question.

Full CISM Practice