nerdexam
Isaca

CISM · Question #892

Which of the following should review and approve the objectives within an organization's information security framework?

The correct answer is B. Information security steering committee. The information security steering committee is the appropriate governance body to review and approve security framework objectives because it represents cross-functional leadership (business, IT, legal, risk) and has the authority to align security objectives with…

Submitted by eva_at· Apr 18, 2026Information Security Governance

Question

Which of the following should review and approve the objectives within an organization's information security framework?

Options

  • ACIO
  • BInformation security steering committee
  • CCISO
  • DInformation security manager

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    72% (13)
  • C
    6% (1)
  • D
    17% (3)

Explanation

The information security steering committee is the appropriate governance body to review and approve security framework objectives because it represents cross-functional leadership (business, IT, legal, risk) and has the authority to align security objectives with organizational strategy. The CIO (A) and CISO (C) are executives who typically propose or develop the framework, but approval should come from a broader governance body to ensure buy-in and balanced oversight. The information security manager (D) is an operational role without the authority or cross-organizational perspective needed for strategic approval.

Topics

#Information Security Governance#Roles and Responsibilities#Steering Committee#Strategic Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice